







The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog
How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

replacements.fyi - performant, safer npm package alternatives
Find more performant and safer replacements for outdated or unnecessary npm packages.

Popular npm Packages in the keyv and Cacheable Namespaces Co...
Popular npm packages keyv and cacheable compromised.

atpkgs
Atpkgs is compatible with the NPM Registry API, so it works with most Node.js package managers.
What If npm Ran on AT Protocol?
A thought experiment about what a package registry would look like if built on atproto.
Just Fucking Use Go - Blain Smith
Hey, dipshit. You know what compiles in two seconds, deploys as a single binary, and doesn't shit itself when a transitive dependency gets yanked from npm at 3am? Go. The same way HTML has been sitting there since the dawn of the goddamn internet waiting for you to stop overcomplicating the frontend, Go has been sitting there for over a decade waiting for you to stop overcomplicating the backend.

npmx - Package Browser for the npm Registry
a fast, modern browser for the npm registry. Search, browse, and explore packages with a modern interface.

Features everyone should steal from npmx
What happens when users design their own package registry frontend

I Built the Same App 10 Times: Evaluating Frameworks for Mobile Performance | Loren Stewart
I needed to choose a framework for a mobile-first app at work. I started comparing Next.js, SolidStart, and SvelteKit, then expanded to 10 frameworks. The measurements revealed dramatic differences in bundle sizes, performance, and the real cost of framework choices.
Vite
A fast build tool for JavaScript apps. Vite has 30 repositories available. Follow their code on GitHub.
EXE
A build tool to pack your web app as a single executable binary with zero runtime dependencies.
GREG ISENBERG on Twitter / X
Apple JUST quietly announced something that’s a lot BIGGER than it looks: "the Mini Apps Partner Program"Apple is admitting that the future of software is embedded, lightweight, vertical mini-apps distributed inside bigger appFor founders who want to make $$ building apps:… pic.twitter.com/jZz7dU6w07— GREG ISENBERG (@gregisenberg) November 14, 2025

keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.

Find the cost of adding an npm package to your app's bundle size.