JCJoel Cheninjchip.hashnode.dev·13h ago · 15 min readRust vs Node.js for a package manager - tuning fyn on pnpm benchmarksRecently I caught the news that pnpm was rewritten in Rust, and I checked it out. It also stirred my interest in an old project of mine: fyn and fynpo. While Rust definitely makes the most of memory, 00
APAkash Palinblogs.akashpal.dev·3d ago · 2 min readWhy I'm building an HTML to PDF tool that works in every languageI'm building a tool that turns HTML into a PDF. It isn't released yet. A beta is coming soon, and I want to share the story from the start. How it started In one of my personal project, AI Question Ge00
JTJAY TANKinjaytank.hashnode.dev·Oct 1 · 10 min readHow to fix package-lock.json merge conflicts (and yarn.lock, poetry.lock, go.sum) the right wayYou rebase your feature branch on main, and git stops halfway: CONFLICT (content): Merge conflict in package-lock.json error: could not apply 3f2c1a9... add date-fns You open the file and there it is00
MTMuhammad Tahirinmtdeveloper.hashnode.dev·Sep 24 · 12 min readModern Open-Source Maintenance: Secure Package Publishing, SemVer, and Automated ScanningThis article was originally published on Muhammad Tahir's Portfolio. Introduction & Industry Context In the modern software engineering landscape of 2026, building applications is less about writing c00
TSTidiane Stanoin4sapi.hashnode.dev·Sep 21 · 8 min readnpm Staged Publish: Secure CI/CD Release WorkflowIntroduction Automated release pipelines do not grant CI systems unrestricted permission to publish packages directly to public registries. GitHub and npm have introduced a new type of scoped access t00
RLRuan Lopesinhermesruanlopes.hashnode.dev·Sep 18 · 8 min readArchitecture of a Self-Hosted Transactional Email Gateway: Decoupled Workers, Argon2id, and Key RotationWhen multiple internal applications need to send transactional emails, embedding SMTP transport logic and template rendering directly into each service introduces tight coupling, unpredictable request00
RSRushabh Shahindepwarden.hashnode.dev·Sep 7 · 4 min readHow npm typosquatting and dependency confusion attacks work (and how to stop them)In February 2021, security researcher Alex Birsan published a paper describing how he had successfully deployed malicious packages to the internal build systems of Apple, Microsoft, PayPal, Shopify, a00
NPNirdesh pokharelinblog.nirdeshpokhrel.com.np·Sep 3 · 5 min readdigit-to-words-nepali: Converting Numbers to Nepali Words, ProperlyIf you've ever built a billing system, an invoice generator, or a cheque-printing tool for a Nepali audience, you already know the pain: turning 1234 into "एक हजार दुई सय चौँतिस" is not a simple looku00
KRKaustubh Raiinkaustubh-cto.hashnode.dev·Sep 2 · 8 min readThe npm Worm Doesn't Care How Good Your CI IsOn 6 August, Singapore's Cyber Security Agency published an advisory about an active npm supply chain attack involving malicious versions of Keyv and related packages, spread by a worm called Shai-Hul00
4F404 Foundersin404-founders.com·Aug 29 · 5 min readnpm ClickFix: 24 Packages Weaponize MirrorsTwenty-four npm packages published between August 4 and August 24, 2026 do not install malware when you run npm install. Instead, they turn trusted package mirrors into free phishing hosting. CVE: N/00