#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
npm’s Defaults Are Bad
·
Andrew Nesbitt
·
March 31, 2026, 4:08 p.m.
Javascript
npm
Security
package managers
npm
Javascript
supply chain security
software development
Summary
The author argues that npm's default settings contribute significantly to JavaScript's supply chain security issues, suggesting that these defaults should be re-evaluated to enhance security.
Read full post on nesbitt.io →
MORE POSTS LIKE THIS
What is npm doing to protect the JavaScript ecosystem – and is it enough?
Thestack ·
Jun 16, 2026
Open Source
Cybersecurity
npm: install before test
Thiago Perrotta ·
Mar 19, 2025
npm
Javascript
How to Create an npm Library
freeCodeCamp.org ·
Feb 7, 2025
npm
YARN
Starlight 0.42
Astro ·
Sep 2, 2026
Javascript
software development
A fun debugging story from this weekend
Juha-Matti Santala ·
Aug 29, 2026
Debugging
Javascript
Lessons learned building an extended standard library for Rust (stdx)
Guillaume Kerkour ·
Aug 27, 2026
Rust
software development
Discover more posts →
AUTHOR
Sponsored
Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →
BLOG POST FEATURED ON
Hacker News
3 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google