starting today, developers building npm projects on @github Actions can request a provenance statement to be published alongside their package, giving consumers a verifiable way to link a package back to its source repository and build instructions.
github.blog/2023-04-19-int…
Now you can create tokens with fine-grained permissions for automating your publishing and org management workflows. And a new code explorer allows you to view content of a package directly in the npm portal. github.blog/2022-12-06-new…
⚡️ #7: Use npm query and jq to dig into your dependencies youtube.com/watch?v=h_Zpix…
You can use the new "npm query" command and jq to answer interesting questions about your package's dependencies
#terminalrocks
Today we opened an RFC with a proposal of how npm can collaborate with @projectsigstore to link packages to their source and build, a significant improvement to the supply chain security of the JavaScript ecosystem. github.blog/2022-08-08-new…
🚀 we just shipped npm v8.16.0 with the new `npm query` command
📦 this new feature allows developers to quickly ask & answer questions about their project's dependencies. you can learn more here: github.blog/changelog/2022…
⬇️ to get it now, run:
$ npm install -g npm
We've launched a number of security enhancements to npm including:
* Improved login and publish experience /w CLI
* Connecting GitHub + Twitter accounts
* All packages have been resigned and a new command `npm audit signatures`
Read more at: github.blog/2022-07-26-int…
do you publish from a npm workspace & use a root-level ignore file? if so, you should update to npm v8.11.0 or the latest versions of Node.js 16/17/18 to avoid a recently discovered vulnerability that wouldn't respect these files.
read the advisory here: github.co/3zebIPH
GitHub has been actively investigating the attack campaign around stolen OAuth tokens, of which @npmjs was a victim organization. Today we’re sharing our final impact analysis for npm as well as additional findings. github.blog/2022-05-26-npm…
GitHub has been actively investigating the attack campaign around stolen OAuth tokens, of which @npmjs was a victim organization. Today we’re sharing our final impact analysis for npm as well as additional findings. github.blog/2022-05-26-npm…
🔒 an enhanced npm 2FA experience is now available in public beta. it includes:
* support for physical security keys and biometric devices
* support for multiple second factors
* a new 2FA configuration menu
and more!
github.blog/2022-05-10-enh…
🚀 Our CLI team just shipped their weekly release!
📦 [email protected] makes `npm owner` workspace-aware & also comes with some docs, deps & core updates/fixes.
⬇️ Get it now:
$ npm install -g npm
See more in the changelog:
github.com/npm/cli/releas…
A new @npmjs cli release is out! 🚀
📦 [email protected] adds a new `--install-links` option to opt into packing+install dependencies defined using the `file:` protocol instead of symlinking.
⬇️ Get it now:
$ npm install -g npm
See more in the changelog: github.com/npm/cli/releas…
we've got a jam packed Open RFC call today w/ some exciting topics like: v9 roadmap, `npm query` + dependency selector syntax, command-specific configuration & more...
come join us live at 2pm EST: github.com/npm/rfcs/issue…#npm#nodejs#javascript
It's npm cli release day again! 🎉
🚀 [email protected]
- fixes `npm ci` lock file validation
- fixes parsing aliases in `npm outdated`
- And more!
⬇️ Get it now:
npm install -g npm
See more in the changelog: github.com/npm/cli/releas…
exciting open rfc meeting planned today at 11am pt / 2pm et; we've got a full agenda including new rfcs for package distributions & ux changes to clean up deprecation warnings: github.com/npm/rfcs/issue…
🎙 come join the discussion or watch live on youtube
youtube.com/channel/UCK71W…
we just shipped a number of security-focused improvements to npm including:
- naming access tokens
- enforcing 2FA in your npm orgs
- improved auditing for 2FA adoption in orgs
- selecting teams when adding new org members
read more in our Changelog ⬇️ github.blog/changelog/2022…
316K Followers 3K FollowingThe Twitter account that launched https://t.co/TJyCu2S5ZF. Built on @forem 🌱
On Bluesky @/https://t.co/TJyCu2S5ZF
No DMs — please email us for support!
49K Followers 307 FollowingEl mundo de la tecnología está en constante evolución, y yo estoy aquí para compartir contigo las últimas novedades y tendencias
757 Followers 3K FollowingCat Butt 🐈 NFT Artist - No more then 777 will be made! Butts that bring crypto luck😻 #bitbuttcat #NFT #NFTs #nftart #cryptoart
669 Followers 7K FollowingFounder of QashqAI Voice | Accessible & Cultural AI | Voices beyond borders .🌍 Every voice matters. Silence is never the end.
17K Followers 2K FollowingHe / Him | Product ❄️ | prev GitHub Product, Google Cloud Dev Rel, IBM Open Source Eng | Opinions are potentially wrong, but definitely my own
3K Followers 301 FollowingNews && events related to Toronto's JavaScript community. Join us on Slack: https://t.co/LsjdEb9361 / Give a talk or workshop: https://t.co/ssRdCBmjeD
2K Followers 521 FollowingNode.js TSC • Building the future of JavaScript packages at https://t.co/M29g9G40iB
Previously @Google, @GitHub, @npmjs
https://t.co/obx4j8XXu4
396K Followers 50 FollowingTypeScript is a language for application-scale JavaScript development. It's a typed superset of JavaScript that compiles to plain JavaScript.
93K Followers 13K Followinghttps://t.co/YC7DLnau3Q is a community based news site focused on #JavaScript including #angularjs #reactjs #aureliajs #backbonejs #emberjs #es6 #nodejs
601K Followers 176 FollowingSharing links, news, and humor about JS, TypeScript, and related front-end stuff 💛
Not affiliated with Oracle or Larry Ellison.
339 Followers 313 Followingsoftware engineer on sabbatical | formerly @npmjs, @microsoft |
Come for the cat pics, leave because there's not that many of them.
2K Followers 2K FollowingSenior Director of PM @cloudflare | Formerly @github @microsoft. Mostly tech, security, Star Trek 🖖🏻, with a sprinkle of far left political outrage.
5K Followers 982 FollowingDesigner, maker, and systems thinker. Senior Staff Software Engineer @webflow. I love scrappy ideas, steady progress, and solving problems.
3K Followers 706 Followingsoftware engineer ⚙️ digital nomad ✈️ i tweet about people, places and things ✨ opinionated about food 🍜 i'm a real mexicana v3.3 🇲🇽
No recent Favorites. New Favorites will appear here.