31.
32.
You Should Not Update Your Dependencies
(news.ycombinator.com)
33.
34.
GitHub introduces staged publishing and new install-time controls for NPM
(news.ycombinator.com)
35.
Deno 2.8
(news.ycombinator.com)
36.
Uv is fantastic, but its package management UX is a mess
(news.ycombinator.com)
37.
GitHub links repo breach to TanStack npm supply-chain attack
(bleepingcomputer.com)
38.
39.
Grafana breach caused by missed token rotation after TanStack attack
(bleepingcomputer.com)
40.
Dumb ways for an open source project to die
(news.ycombinator.com)
41.
Dumb Ways for an Open Source Project to Die
(news.ycombinator.com)
42.
Show HN: Id-agent – Token efficient UUID alternative for AI agents
(news.ycombinator.com)
43.
New Shai-Hulud malware wave compromises 600 npm packages
(bleepingcomputer.com)
44.
Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
(news.ycombinator.com)
45.
Leaked Shai-Hulud malware fuels new npm infostealer campaign
(bleepingcomputer.com)
46.
'No way to prevent this,' says only package manager where this regularly happens
(news.ycombinator.com)
47.
Popular node-ipc npm package compromised to steal credentials
(bleepingcomputer.com)
48.
OpenAI confirms security breach in TanStack supply chain attack
(bleepingcomputer.com)
49.
50.
Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain
(darkreading.com)
51.
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
(bleepingcomputer.com)
52.
Show HN: Safe-install – safer NPM installs with trusted build dependencies
(news.ycombinator.com)
53.
Postmortem: TanStack NPM supply-chain compromise
(news.ycombinator.com)
54.
Postmortem: TanStack npm supply-chain compromise
(news.ycombinator.com)
55.
TanStack NPM Packages Compromised
(news.ycombinator.com)
56.
Remembering Planet Source Code: Sharing Code Before GitHub Made It Easy
(news.ycombinator.com)
57.
Ask HN: We just had an actual UUID v4 collision...
(news.ycombinator.com)
58.
OpenClaw Had a Rough Week
(news.ycombinator.com)
59.
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
(darkreading.com)
60.
Official SAP npm packages compromised to steal credentials
(bleepingcomputer.com)