#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Privacy
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
npm’s Defaults Are Bad
·
Andrew Nesbitt
·
March 31, 2026, 4:08 p.m.
package managers
Javascript
npm
Security
Javascript
npm
software development
supply chain security
Summary
The author argues that npm's default settings contribute significantly to JavaScript's supply chain security issues, suggesting that these defaults should be re-evaluated to enhance security.
Read full post on nesbitt.io →
MORE POSTS LIKE THIS
Ship cleaner packages (without the ./dist or ./src folder) by publishing a subfolder to NPM
Original Content – Bram.us ·
Sep 20, 2026
Original Content
npm
npm Supply Chain Attack Mitigation: What Actually Works
Aleksei Aleinikov ·
Sep 9, 2026
npm-supply-chain-attack
supply chain security
What is npm doing to protect the JavaScript ecosystem – and is it enough?
Thestack ·
Jun 16, 2026
Cybersecurity
npm
npm: install before test
Thiago Perrotta ·
Mar 19, 2025
Javascript
npm
How to Create an npm Library
freeCodeCamp.org ·
Feb 7, 2025
npm
YARN
Getting a full-width PR review pane on GitHub temporary private forks
Jamie Tanna ·
Sep 23, 2026
Javascript
github
Discover more posts →
AUTHOR
Advertise
Sponsor diff.blog
Put your product in front of developers who read and write about their craft. One exclusive sponsor at a time.
Become a sponsor →
BLOG POST FEATURED ON
Hacker News
3 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google
By continuing, you agree to our
Privacy Policy
.