DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Topics
Follow your own topics →
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

npm’s Defaults Are Bad

230 · Andrew Nesbitt · March 31, 2026, 4:08 p.m.
package managers Javascript npm Security Javascript npm software development supply chain security
Summary
The author argues that npm's default settings contribute significantly to JavaScript's supply chain security issues, suggesting that these defaults should be re-evaluated to enhance security.
Read full post on nesbitt.io →
MORE POSTS LIKE THIS
What is npm doing to protect the JavaScript ecosystem – and is it enough?
Thestack · Jun 16, 2026
Cybersecurity npm
npm: install before test
Thiago Perrotta · Mar 19, 2025
Javascript npm
How to Create an npm Library
freeCodeCamp.org · Feb 7, 2025
npm YARN
What's missing to have reproducible builds on PyPI
brettcannon · Aug 16, 2026
Python packaging
Build a DIY pipeline for a trusted software supply chain
Red Hat · Aug 13, 2026
Security DevOps
Cleanup, Speedup, Levelup open source at e181
Opensourcesecurity · Aug 10, 2026
Open Source Javascript
Discover more posts →
AUTHOR
BLOG POST FEATURED ON

Placeholder image
Hacker News

3 points

Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google