https://github.com/wesleytodd
Full report →
socket.dev/blog/malicio... #dotnet
https://eslint.org/donate
https://eslint.org/donate
I am fully on board with a message of:
Show me that you looked at the code at all.
github.com/expressjs/ex...
I am fully on board with a message of:
Show me that you looked at the code at all.
github.com/expressjs/ex...
socket.dev/blog/npm-rev... #NodeJS #JavaScript
socket.dev/blog/npm-rev... #NodeJS #JavaScript
socket.dev/blog/npm-rev... #NodeJS #JavaScript
We're looking for stellar frontend developers. DM me
We're looking for stellar frontend developers. DM me
We will release new versions of v20, v22, v24, v25 release lines on or shortly after the 15th of December 2025 in order to address:
* 3 high severity issues.
* 1 low severity issue.
* 1 medium severity issue.
nodejs.org/en/blog/vuln...
We will release new versions of v20, v22, v24, v25 release lines on or shortly after the 15th of December 2025 in order to address:
* 3 high severity issues.
* 1 low severity issue.
* 1 medium severity issue.
nodejs.org/en/blog/vuln...
socket.dev/blog/shai-hu...
socket.dev/blog/shai-hu...
socket.dev/blog/shai-hu...
What was that again about trusted publishing? You need to trust your CI for it's threat model to apply? Guess maybe that's a bad place to put our trust.
What was that again about trusted publishing? You need to trust your CI for it's threat model to apply? Guess maybe that's a bad place to put our trust.
Hate on Austin all you want (especially since it’s in Texas) but I still love this place.
Hate on Austin all you want (especially since it’s in Texas) but I still love this place.
#javascript #nodejs #packages
#javascript #nodejs #packages
You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
Here is that guidance 👇
We've released updated guidance to help maintainers reduce exposure, strengthen release processes, and protect the ecosystem: openjsf.org/blog/publish...
Here is that guidance 👇