What is npm doing to protect the JavaScript ecosystem – and is it enough?
The Stack
Jun 17, 20261 min read
pm’s attempts to make package publishing safer haven’t stemmed the relentless supply chain attacks: Are they on the right track?
The longer I spend researching and having fascinating conversations, the longer my pieces turn out, because I want to squeeze in as many of the great things people have said to me. Plus, this is a topic almost as big as the JavaScript ecosystem.
What is npm doing to protect the JavaScript ecosystem
npm’s attempts to make package publishing safer haven’t stemmed the relentless supply chain attacks: Are they on the right track?
- npm
- JavaScript
- security
- provenance
- identity
- developer
- open source
Did you enjoy this article?
Recommend it — Standard Reader surfaces well-loved writing to more readers across the network.