Blogs

npm Registry Code Signing

Socket

Socket explains the newly released npm provenance provided by GitHub.

Visit Site

Blogs Socket

BlogsUpdated and Ongoing Supply Chain Attack Targets CrowdStrike npm PackagesSocket BlogsHow to Protect Your Projects from the Risks of Deprecated npm PackagesSocket BlogsPopular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain AttackSocket BlogsSupply Chain Attack on Axios Pulls Malicious Dependency from npmSocket BlogsSuno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music ScrapingSocket BlogsSigning is Just the StartSocket BlogsDocs-as-code solutions for API teams: how to choose the right platform in 2026Mintlify BlogsMintlify Alternatives: What to Consider (and Why There's No True Substitute)Mintlify LearnBuild a Presentation Coaching Application with Recall - Deepgram Blog ⚡️Deepgram LearnNo Code Transcription: Simplifying Workflows with Deepgram and Make.comDeepgram NewsOso Unbundles Security AuthorizationThenewstack BlogsEmpower Your Team with Policy as CodePulumi BlogsFive Years of Infrastructure as CodePulumi BlogsNew Policy as Code Capabilities with CrossGuardPulumi BlogsGodoc: documenting Go code - The Go Programming LanguageGo ResourcesManaging dependencies - The Go Programming LanguageGo BlogsHow Hunch supercharged AI workflows with Modal SandboxesModal BlogsHow to Use Your Own RegistryDocker ResourcesESLINT_CONFIGURATIONVercel BlogsYou can just ship agentsVercel