The three pillars of JavaScript bloat
(news.ycombinator.com)
1.
2.
The Three Pillars of JavaScript Bloat
(news.ycombinator.com)
3.
4.
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
(bleepingcomputer.com)
5.
GlassWorm Malware Evolves to Hide in Dependencies
(darkreading.com)
6.
Glassworm is back: A new wave of invisible Unicode attacks hits repositories
(news.ycombinator.com)
7.
Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
(news.ycombinator.com)
8.
9.
10.
Vite 8.0 Is Out
(news.ycombinator.com)
11.
Show HN: Rudel – Claude Code Session Analytics
(news.ycombinator.com)
12.
Secure Secrets Management for Cursor Cloud Agents
(news.ycombinator.com)
13.
If It Quacks Like a Package Manager
(news.ycombinator.com)
14.
TypeScript 6.0 RC
(news.ycombinator.com)
15.
A GitHub Issue Title Compromised 4k Developer Machines
(news.ycombinator.com)
16.
Google Workspace CLI
(news.ycombinator.com)
17.
Show HN: Gapless.js – gapless web audio playback
(news.ycombinator.com)
18.
A rabbit hole in 5 commits
(news.ycombinator.com)
19.
LLM=True
(news.ycombinator.com)
20.
Pi – A minimal terminal coding harness
(news.ycombinator.com)
21.
Pi – a minimal terminal coding harness
(news.ycombinator.com)
22.
I'm helping my dog vibe code games
(news.ycombinator.com)
23.
NPM install is stealing your passwords – I built a tool to catch it
(news.ycombinator.com)
24.
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
(darkreading.com)
25.
I Don't Like Magic
(news.ycombinator.com)
26.
NPMX – a fast, modern browser for the NPM registry
(news.ycombinator.com)
27.
Two new RSC protocol vulnerabilities uncovered
(news.ycombinator.com)
28.
Show HN: Safe-NPM – only install packages that are +90 days old
(news.ycombinator.com)
29.
NPM flooded with malicious packages downloaded more than 86k times
(news.ycombinator.com)
30.
Malicious NPM packages fetch infostealer for Windows, Linux, macOS
(bleepingcomputer.com)