#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
Discover the best posts from developers and engineering teams, all in one place.
Join now
→
Learn more
TOPICS
npm’s Defaults Are Bad
230
·
Andrew Nesbitt
·
March 31, 2026, 4:08 p.m.
package managers
Javascript
npm
Security
npm
Javascript
supply chain security
software development
Summary
The author argues that npm's default settings contribute significantly to JavaScript's supply chain security issues, suggesting that these defaults should be re-evaluated to enhance security.
Read full post on nesbitt.io →
MORE POSTS LIKE THIS
What is npm doing to protect the JavaScript ecosystem – and is it enough?
Thestack ·
Jun 16, 2026
Cybersecurity
npm
npm: install before test
Thiago Perrotta ·
Mar 19, 2025
npm
Javascript
How to Create an npm Library
freeCodeCamp.org ·
Feb 7, 2025
npm
YARN
Security Baked Into the JVM: the Safe Codebase Audit Pipeline
nfrankel ·
Jul 19, 2026
Java
jvm
Igalia at GUADEC 2026
Igalia ·
Jul 15, 2026
News
igalia
Escape from Average (#note)
Stefanjudis ·
Jul 11, 2026
note
AI
Discover more posts →
AUTHOR
BLOG POST FEATURED ON
Hacker News
3 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google