cd/entity/npm· home entities npm
grep -l @npm /news/*.json | wc -l → 297

npm

mentions 297 type Organization page 2/15 feed RSS

// recent coverage 297 mentions

08:33
2026-08-18
github.com
developer-tools

Show HN: There are many factories, but this one's *yours

Mikael Weiss released Penguin, an open-source TypeScript workflow builder that lets developers define their own software factory workflows with deterministic pauses and adapters, addressing flaws in e…

04:31
2026-08-18
dev.to
ai-safety

Fixing ai code autofix security flaws: My AST checker

A developer detailed how AI autofix tools like GitHub Copilot can introduce subtle security vulnerabilities due to incomplete contextual understanding, citing the Snowflake breach as a case in point. …

00:00
2026-08-17
dev.to
developer-tools

Four Failures That Made a Weekly launchd Job Actually Run

A developer built a weekly launchd job that automatically distributes AI-learned skills from Claude Code's global skills folder into every local git repository, eliminating the need for manual copying…

13:43
2026-08-15
stephen-cresswell.com
developer-tools

Yadda 3.0.0: BDD in the Age of AI Agents

Yadda 3.0.0, a BDD library for JavaScript, was published to npm by its maintainer Stephen Cresswell, who used Claude Code with Opus 4.8 to modernize the codebase in about a day. The release removes ob…

13:58
2026-08-14
dev.to
ai-tools

CrawlForge v5.0.0: Security, Correctness, MCP Spec

CrawlForge MCP Server v5.0.0 addresses a critical SSRF vulnerability that allowed IP-literal URLs to bypass hostname-based guards, potentially exposing loopback, link-local, and cloud metadata endpoin…

23:42
2026-08-13
opensourcemalware.com
ai-safety

The OpenSourceMalware Show #17

GitHub has revoked npm granular access tokens' ability to bypass two-factor authentication for sensitive account, organization, and package management actions, closing a security gap. The announcement…

06:26
2026-08-13
bramo.ai
artificial-intelligence

My AI agents shipped 128 releases of a product no one ever used

A solo founder shipped 128 releases of an SDLC orchestrator for AI coding agents that never gained a single external user, then built a second product with 442 passing tests that broke in real use, ac…

14:07
2026-08-12
github.com
developer-tools

anti-slop: Opinionated Oxlint rules

Developer Dillon Mulroy released anti-slop, an open-source (MIT) plugin of opinionated Oxlint rules that reject low-evidence and low-signal TypeScript and JavaScript patterns, distributed via source a…

00:00
2026-08-12
ai2rules.dev
ai-tools

A Scanner Flagged Our Supply-Chain Package. It Was Right.

Socket, a supply-chain security scanner, flagged the npm package ai2rules-harness with a Supply Chain Security score of 64%, prompting its developer to discover that the package's postinstall script f…

00:00
2026-08-12
ai2rules.dev
ai-safety

The Switch Inside the Room

A coding-agent security tool shipped by an unnamed developer was found to have three critical flaws, including a kill switch at `.claude/gate-off` that the agent could create without denial, allowing …

← prev page 2 / 15 next →
// co-occurs with top 8 entities
// topics top 6 topics