Hackernews posts about Pnpm
- NPM retires audit endpoint; breaks pnpm audit (github.com)
- pnpm v11 Released (pnpm.io)
- Show HN: SafeInstall – local install-time guardrails for NPM/pnpm/bun (www.safeinstall.dev)
- pacquet: the official pnpm rewrite in Rust (github.com)
- pnpm v11 is almost here (twitter.com)
- Show HN: Dependicus, a dashboard for your monorepo's dependencies (descriptinc.github.io)
- Show HN: Drag-and-Drop in the Terminal (github.com)
- NPM website was down (status.npmjs.org)
- Official SAP NPM packages compromised to steal credentials (www.bleepingcomputer.com)
- Bitwarden CLI NPM package has been compromised (opensourcemalware.com)
- Mini Shai-Hulud: Bun Payloads Hit SAP NPM Packages (www.stepsecurity.io)
- Another NPM supply chain worm is tearing through dev environments (www.theregister.com)
- NPM: Putting the Brown in Brownout (ryanbigg.com)
- TeamPCP Campaign Spreads to NPM via a Hijacked Bitwarden CLI (research.jfrog.com)
- Intercom-client NPM package and lightning PyPI packages compromised (opensourcemalware.com)
- Bitwarden CLI Backdoored on NPM for 93 Minutes (hackingpassion.com)
- StackGraveyard.dev – Live mortality scores for NPM packages (www.stackgraveyard.dev)
- SAP Cap NPM Packages Hit by Supply Chain Attack (socket.dev)
- NPM Slop and Wonky Software Supply Chains (simonramstedt.com)
- Features everyone should steal from npmx (nesbitt.io)