Skip to main content

Search

Items tagged with: npm


So is #Node and #NPM one big infosec dumpster fire or what? Asking for a friend...
#node #npm


‘No Way To Prevent This,’ Says Only Package Manager Where This Regularly Happens | Kevin Patel

「 “It’s a shame, but what can you do? This is just the price of building modern web apps,” said Senior Frontend Engineer Mark Vance, echoing the sentiments of a community that completely relies on a 40-level-deep nested tree of unvetted packages maintained by pseudonymous strangers to capitalize a single string 」

kevinpatel.xyz/posts/no-way-to…

#npm #satire #cybersecurity


Bitwarden-cli 2026.4.0 compromised. Ugh.

Not something one likes to read in the morning. :(

socket.dev/blog/bitwarden-cli-…

#bitwarden #bitwardencli #npm #security