







Drydock lets npm, PyPI, and VS Code maintainers review the exact package artifact before an npm stage publish or gated release goes live.

What If npm Ran on AT Protocol?
A thought experiment about what a package registry would look like if built on atproto.
Inside the keyv npm Supply Chain Compromise | Snyk
The keyv npm compromise used preinstall malware, trusted provenance, and IDE hooks to target developer and CI credentials. Learn how to detect and respond.

The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog
How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

npmx - Package Browser for the npm Registry
a fast, modern browser for the npm registry. Search, browse, and explore packages with a modern interface.

atproto for local-first publishing
Exploring an effortless private to publishing pipeline for local-first software leveraging the AT Protocol’s global distribution.

Daniel Roe & Matias Leandro Capeletto - npmx: a fast, modern browser for the npm registry
keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.

AWS DevOps Agent adds release management capabilities to assess code changes before production (preview) | Amazon Web Services
AWS DevOps Agent now offers release management capability in preview, reviewing code changes for release readiness and running autonomous release testing to help you ship code to production safely and with confidence.

Direnv - Pixi
Pixi Documentation — Next-gen package manager for reproducible development setups
singi-labs/barazo-workspace
pnpm workspace root for Barazo forum development — shared configuration, tooling, and cross-package dependency management
defcon-26-workshop-attacking-and-auditing-docker-containers/dryrun.todo at master · appsecco/defcon-26-workshop-attacking-and-auditing-docker-containers
DEF CON 26 Workshop - Attacking & Auditing Docker Containers Using Open Source - appsecco/defcon-26-workshop-attacking-and-auditing-docker-containers