Verifiedapp Blog
Home All posts

Tag

#npm

Supply Chain

The 3 npm settings that stop most supply-chain attacks (lockfile, npm ci, cooldown)

Most dependency supply-chain risk is blunted by three boring npm settings. They are not glamorous, but they remove the easy ways a bad package slips in.

Jun 29, 2026 · 3 min read
Supply Chain

The npm supply-chain attacks every shipper should know in 2026

Your app ships dozens of packages you never chose. When one gets hijacked, you ship the attack too. Here is the pattern, the big recent incidents, and the defenses.

May 21, 2026 · 3 min read
© VerifiedApp — automated security scanning & trust badges. RSS