|
|
Log in / Subscribe / Register

Is this our chance to stop using NPM?

Is this our chance to stop using NPM?

Posted Jun 1, 2026 15:47 UTC (Mon) by zdzichu (subscriber, #17118)
In reply to: Is this our chance to stop using NPM? by jpeisach
Parent article: Multiple redhat-cloud-services npm packages compromised (StepSecurity Blog)

The article is about RedHat compromise. NPM is owned and operated by Microsoft. You seem confused.

And even if we were to stop using NPM – where's your alternative?


to post comments

Is this our chance to stop using NPM?

Posted Jun 1, 2026 18:02 UTC (Mon) by jepsis (subscriber, #130218) [Link] (1 responses)

Use pnpm instead of npm, enable the strictest security settings, and configure a reasonable release cooldown period.

Is this our chance to stop using NPM?

Posted Jun 3, 2026 0:40 UTC (Wed) by fredi@lwn (subscriber, #65912) [Link]

I like Javascript in general. However, here IMO is not the language in general as much as the fast moving changes in package managers of various languages change. And it is impossible following each of pip / pip3 / npm / upnp (jociing here) / whatever for each language, unless one has unlimited hours per day, and no real life.

Is this our chance to stop using NPM?

Posted Jun 1, 2026 23:40 UTC (Mon) by AdamW (subscriber, #48457) [Link]

It's about a compromise of upstream NPM repositories maintained by Red Hat. It's a complex situation involving multiple people, systems and companies.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds