Skip to content
All tags

#npm

3 posts

pi-mono Deep Dive 16: Release Pipeline — Lockstep Versioning, Binary Build, Trusted Publishing From Code to npm

Full release flow: Lockstep versioning (all packages same version), CHANGELOG, local smoke, release script, Bun+Node binary build, npm-shrinkwrap, GitHub Actions OIDC trusted publishing, R2 release marker, pi.dev/api/latest-version, announcement verification.

Socket.dev: Blocking Malicious Package Behavior at Dependency-Diff Time

Socket.dev goes beyond CVEs by analyzing install scripts, obfuscation, network and shell access, and ownership changes when packages enter a dependency diff.

techguide

False positives in Node.js image vulnerability scans? Separate app packages from npm built-ins first

When reviewing vulnerability scan results for a Node.js Docker image, you can't just look at package names. First distinguish between project dependencies and the packages bundled with npm inside the base image — otherwise you'll fix the wrong thing.