#fair-package-manager

[ follow ]
Software development
fromDevOps.com
4 days ago

Waydev Adds Ability to Track How Much AI Code Winds Up in Production - DevOps.com

Waydev's platform enhances DevOps by tracking AI coding tool impacts on workflows and ROI for software engineering teams.
Information security
fromDevOps.com
3 days ago

The Open Source Trap: Why Trust Isn't a Security Strategy - DevOps.com

The software supply chain is vulnerable due to reliance on under-resourced open source maintainers, requiring active organizational support for security.
Agile
fromdzone.com
3 days ago

Rethinking Risk in Agile Software Development

Agile must integrate risk management into workflows to avoid hidden risks and instability in complex software systems.
Web frameworks
fromInfoQ
6 days ago

Empower Your Developers: How Open Source Dependencies Risk Management Can Unlock Innovation

Improving security in open-source dependencies is essential for effective risk management and innovation.
#javascript
Node JS
fromCSS-Tricks
4 days ago

A Well-Designed JavaScript Module System is Your First Architecture Decision | CSS-Tricks

JavaScript modules enable private scopes and controlled global access, essential for managing large programs and avoiding conflicts.
Node JS
fromCSS-Tricks
4 days ago

A Well-Designed JavaScript Module System is Your First Architecture Decision | CSS-Tricks

JavaScript modules enable private scopes and controlled global access, essential for managing large programs and avoiding conflicts.
#github
fromTheregister
6 days ago
JavaScript

GitHub recalls Phabricator with preview of Stacked PRs

GitHub's Stacked PRs feature simplifies the review process for large pull requests by allowing them to be organized in a manageable stack.
JavaScript
fromTheregister
6 days ago

GitHub recalls Phabricator with preview of Stacked PRs

GitHub's Stacked PRs feature simplifies the review process for large pull requests by allowing them to be organized in a manageable stack.
Information security
fromThe Hacker News
6 days ago

New PHP Composer Flaws Enable Arbitrary Command Execution - Patches Released

Two high-severity vulnerabilities in Composer could allow arbitrary command execution through command injection flaws in the Perforce VCS driver.
DevOps
fromDevOps.com
2 weeks ago

Survey Surfaces Increased Reliance on Open Source Software to Build Apps - DevOps.com

Open source software adoption is prevalent, with 49% of IT professionals reporting increased usage, primarily due to cost savings and avoiding vendor lock-in.
Angular
fromMedium
2 weeks ago

A dev's guide to prompting Bit Cloud the right way

Bit Cloud prioritizes a component-first approach, proposing structure before implementation to facilitate better architectural decisions.
Ruby on Rails
fromRubyflow
2 weeks ago

Ruby 4.0 Default to Bundled Gems: What Does That Mean, Anyway?

Ruby 4.0 has transitioned certain gems from 'default' to 'bundled status', impacting developers' understanding of core libraries.
#open-source
Python
fromThe Hacker News
2 weeks ago

The State of Trusted Open Source Report

AI is reshaping software development and security, influencing container image usage and vulnerability management.
Python
fromThe Hacker News
2 weeks ago

The State of Trusted Open Source Report

AI is reshaping software development and security, influencing container image usage and vulnerability management.
#nodejs
Node JS
fromTreehouse Blog
1 week ago

How Node.js Lets JavaScript Run on the Server

Node.js allows JavaScript to run on servers, enabling full stack development with a single language.
Node JS
fromTreehouse Blog
1 week ago

How Node.js Lets JavaScript Run on the Server

Node.js allows JavaScript to run on servers, enabling full stack development with a single language.
Node JS
fromDEV Community
1 month ago

I Scanned 6 Popular Node.js Repos for Undocumented Environment Variables. Here's What I Found.

Many popular Node.js projects lack comprehensive documentation for process.env variables, leading to potential configuration issues.
fromInfoQ
2 weeks ago

Module Federation 2.0 Reaches Stable Release with Wider Support Outside of Webpack

The dynamic type hints feature in Module Federation 2.0 dramatically streamlines the development process by automatically generating and loading types from remote modules, eliminating the need for shared type packages.
Angular
Ruby on Rails
fromTheregister
2 weeks ago

Ruby Central seeks closure with RubyGems fracture report

Ruby Central published a report on the September 2025 RubyGems fracture, detailing governance issues and future steps for community involvement.
#cybersecurity
Node JS
fromThe Hacker News
2 weeks ago

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

36 malicious npm packages disguised as Strapi CMS plugins facilitate exploitation and credential harvesting.
Information security
fromThe Hacker News
1 month ago

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

A supply chain attack on Trivy scanner has led to the emergence of CanisterWorm, compromising numerous npm packages.
Software development
fromMedium
2 weeks ago

Zero-Effort Production Debugging: How I Automated Bug Fixes for My Side Project

Automating bug fixes with an AI agent streamlines maintenance for full-stack applications, enabling zero-effort management of errors.
Python
fromRealpython
3 weeks ago

How to Use Git: A Beginner's Guide - Real Python

Git is a version control system that tracks changes locally, while GitHub is an online platform for hosting Git repositories.
#npm
Node JS
fromInfoQ
2 weeks ago

Axios npm Package Compromised in Supply Chain Attack

A significant supply chain attack on Axios introduced a Remote Access Trojan via hijacked maintainer accounts, affecting numerous developer environments.
Node JS
fromInfoQ
2 weeks ago

Axios npm Package Compromised in Supply Chain Attack

A significant supply chain attack on Axios introduced a Remote Access Trojan via hijacked maintainer accounts, affecting numerous developer environments.
Software development
fromDevOps.com
2 weeks ago

Why Code Validation is the Next Frontier - DevOps.com

Shared staging environments are inadequate for modern development; isolated, on-demand setups are needed for effective validation.
Java
fromInfoQ
1 month ago

Andres Almiray on How to Release Any Software to Any OS with JReleaser

Andres Almiray, a Java Champion with 20 years of open-source contributions, developed JReleaser as a CLI tool addressing supply chain security, reproducible builds, and release automation in the Java ecosystem.
JavaScript
fromDEV Community
1 month ago

I Built an npm Package and Tracked Every Download for Two Weeks. Here's the Data.

textlens, a zero-dependency text analysis toolkit, achieved 977 downloads in week one but dropped 94% to 63 downloads in week two, settling at 16 daily downloads versus competitors' 2,100 daily downloads.
#linux
Node JS
fromZDNET
3 weeks ago

How this strange little distro can boost your Linux skills

Peropesis is a command-line-only Linux distribution designed for learning the CLI.
fromZDNET
2 months ago
Software development

The 6 Linux distros I expect to rule 2026 - as someone who's tested hundreds (and for decades)

fromZDNET
2 months ago
Software development

5 Linux file managers to try when your GUI just won't do - they're all free

fromZDNET
2 months ago
Software development

I replaced Windows with Linux, and there's only one feature I miss

fromZDNET
2 months ago
Software development

The 6 Linux distros I expect to rule 2026 - as someone who's tested hundreds of them

Node JS
fromZDNET
3 weeks ago

How this strange little distro can boost your Linux skills

Peropesis is a command-line-only Linux distribution designed for learning the CLI.
fromZDNET
2 months ago
Software development

The 6 Linux distros I expect to rule 2026 - as someone who's tested hundreds (and for decades)

fromZDNET
2 months ago
Software development

5 Linux file managers to try when your GUI just won't do - they're all free

fromZDNET
2 months ago
Software development

I replaced Windows with Linux, and there's only one feature I miss

fromZDNET
2 months ago
Software development

The 6 Linux distros I expect to rule 2026 - as someone who's tested hundreds of them

Software development
fromInfoQ
1 month ago

Stripe Engineers Deploy Minions, Autonomous Agents Producing Thousands of Pull Requests Weekly

Minions are autonomous coding agents at Stripe that generate production-ready pull requests with minimal human intervention.
Web frameworks
fromMedium
1 month ago

My 8-Year-Old Open-Source Project was a Victim of a Major Cyber Attack

A popular open-source project fell victim to a supply-chain attack through a development workflow loophole, threatening years of work and project reputation.
Software development
fromZDNET
1 month ago

EndeavorOS Titan is one of the most unique Arch-based Linux distros I've tried - here's why

EndeavorOS Titan enhances usability with new features and tools for GPU management.
Miscellaneous
fromTheregister
1 month ago

Open source package repositories face sustainability crisis

Open source repositories face unsustainable demand from companies misusing them as CDNs, prompting consideration of tiered payment systems where heavy users pay while individual developers remain free.
Software development
fromZDNET
1 month ago

EndeavorOS Titan stands out among Arch-based Linux distros - here's why

EndeavorOS Titan enhances the Arch-based distribution with updated applications, streamlined installation, improved GPU support, and a new eos-hwtool command-line utility for managing GPU drivers.
Node JS
fromDEV Community
1 month ago

Why I Stopped Maintaining .env.example by Hand

A new tool automatically discovers environment variables used in Node.js code to prevent stale .env.example files from causing deployment failures.
#linux-distributions
fromZDNET
2 months ago
Software development

8 Linux distros I always recommend first to developers - and why

fromZDNET
2 months ago
Software development

8 Linux distros I always recommend first to developers - and why

#agentic-workflows
Philosophy
fromMedium
2 months ago

Why code is not the source of truth

Design specifications and blueprints, not implementation code, are the authoritative source of truth; implementation is derived from and judged against originating design authority.
fromZDNET
2 months ago

Atomic vs immutable Linux: How to decide which distro type is right for you

The updates are installed onto a different (and isolated) system image or subvolume. Once the update finishes successfully, you can switch to the new system by rebooting. Again, if the update isn't 100% successful, it will not happen. And because this all occurs on a separate partition (or image), you don't have to worry about it affecting your system's current state.
DevOps
JavaScript
fromInfoWorld
2 months ago

Beyond NPM: What you need to know about JSR

The JavaScript Registry simplifies and secures JavaScript package creation, distribution, and consumption while addressing NPM's TypeScript complexity and provenance shortcomings.
Software development
fromZDNET
1 month ago

8 powerful Apt commands I use to unlock hidden features - and why they're so handy

The Debian/Ubuntu apt package manager offers advanced commands beyond basic install and remove functions for more powerful system management.
fromThe Verge
2 months ago

I went back to Linux and it was a mistake

A few months ago, I decided to breathe new life into a 2019 Dell XPS 15 that had been collecting dust for a couple of years. Despite its (at the time) high-end Core i7 CPU and 32GB of RAM, Windows was frustratingly slow on it. The fan was constantly at full throttle even when the machine was idle, and it regularly failed to install updates.
Tech industry
fromZDNET
1 month ago

I found the best Linux server distros for your home lab

I've had several incarnations of the self-hosted home lab for decades. At one point, I had a small server farm of various machines that were either too old to serve as desktops or that people simply no longer wanted. I'd grab those machines, install Linux on them, and use them for various server purposes. Here are two questions you should ask yourself:
DevOps
Python
fromRealpython
2 months ago

uv vs pip: Python Packaging and Dependency Management - Real Python

Choose pip for broad compatibility and ecosystem support; choose uv for faster installs, reproducible environments, cleaner uninstalls, and streamlined new-project workflows.
Node JS
fromTechzine Global
1 month ago

New npm browser npmx addresses shortcomings of npmjs

Npmx, an open-source alternative interface to npm's official website, addresses widespread developer dissatisfaction with the current package registry's user experience and presentation of package information.
fromTechzine Global
1 month ago

Go developer questions effectiveness of Dependabot

Dependabot sounded the alarm on a large scale. Thousands of repositories automatically received pull requests and warnings, including a high vulnerability score and signals about possible compatibility issues. According to Valsorda, this shows that the tool mainly checks whether a dependency is present, without analyzing whether the vulnerable code is actually accessible within a project.
Information security
Software development
fromZDNET
1 month ago

Windows 12 could be the tipping point that finally pushes you to Linux - here's why

Microsoft's established pattern of controversial Windows releases will likely drive significant user migration to Linux with Windows 12.
DevOps
fromDbmaestro
4 years ago

18 Best DevOps Quotes to Inspire DevOps Teams

DevOps success depends on automation, cultural change, trust, communication, and continuous improvement through Agile practices and visible demonstrations of value.
fromTheregister
1 month ago

npmx alternative to npmjs released to fix pain of rpm

npmx is about speed and simplicity. It gives you useful data like install size, module format and outdated dependencies ... we're also building social features into npmx because open source is better when it's easier to connect with the people behind the packages.
Node JS
fromInfoWorld
2 months ago

Unplugged holes in the npm and yarn package managers could let attackers bypass defenses against Shai-Hulud

saving lockfile integrity checks (package-lock.json, pnpm-lock.yaml, and others) to version control (git). The lockfile records the exact version and integrity hash of every package in a dependency tree. On subsequent installs, the package manager checks incoming packages against these hashes, and if something doesn't match, installation fails. If an attacker compromises a package and pushes a malicious version, the integrity check should catch the mismatch and block it from being installed.
Information security
fromZDNET
2 months ago

Need to manage virtual machines on Linux? I found an easier way

I recently wrote about my migration away from VirtualBox to KVM/Virt-Machine for my virtual machine needs. I've found those tools to be far superior (albeit with a bit more of a learning curve) than VirtualBox. Since then, however, I've found another method of working with KVM (the Linux kernel virtual machine technology), one that not only allows me to create and manage virtual machines on my local computer, but also from any machine on my LAN. That tool is Cockpit, which makes managing your Linux machines considerably easier.
DevOps
fromTheregister
2 months ago

Sudo's maintainer needs resources to keep utility updated

Sudo, for those not familiar with Unix systems, is a command-line utility that allows authorized users to run specific commands as another user, typically the superuser, under tightly controlled policy rules. It is a foundational component of Unix and Linux systems: without tools like sudo, administrators would be forced to rely more heavily on direct root logins or broader privilege escalation mechanisms, increasing both operational risk and attack surface.
Information security
fromInfoWorld
1 month ago

Compromised npm package silently installs OpenClaw on developer machines

Researchers have discovered that a compromised npm publish token pushed an update for the widely-used Cline command line interface (CLI) containing a malicious postinstall script. That script installs the wildly popular, but increasingly condemned, agentic application OpenClaw on the unsuspecting user's machine. This can be extremely dangerous, as OpenClaw has broad system access and deep integrations with messaging platforms including WhatsApp, Telegram, Slack, Discord, iMessage, Teams, and others.
Information security
Information security
fromSecurityWeek
2 months ago

'PackageGate' Flaws Open JavaScript Ecosystem to Supply Chain Attacks

Six vulnerabilities in major JavaScript package managers (NPM, PNPM, VLT, Bun) allow bypassing supply chain protections and enable remote code execution.
Software development
fromZDNET
2 months ago

I found a new Linux distro that's a productivity powerhouse right out of the box

Elegance is a Manjaro-based rolling-release Linux distribution that ships with many preinstalled applications and a refined Cinnamon desktop.
Node JS
fromDevOps.com
1 month ago

Malicious NPM Package Gets Downloaded 50K Times Before Discovery - DevOps.com

A malicious npm package downloaded 50,000 times used naming deception and preinstall script hooks to evade detection and compromise Windows, Linux, and macOS systems.
fromTechzine Global
2 months ago

Critical vulnerability in React Native development tool actively exploited

Attackers are actively exploiting a critical vulnerability in React Native's Metro server to infiltrate development environments. The vulnerability, CVE-2025-11953, allows malicious actors to execute code on Windows and Linux systems via exposed development servers. Metro is React Native's default JavaScript bundler during application development and testing. In many configurations, this server runs locally, but by default, Metro can also bind to external network interfaces. This makes HTTP endpoints available that are intended for development. It is precisely this functionality that now constitutes an attack vector,
Information security
#linux-mint
fromZDNET
2 months ago
Software development

My 5 favorite Linux distros that are ready to use out of the box (no setup required)

fromZDNET
2 months ago
Software development

My 5 favorite Linux distros that are ready to use out of the box (no setup required)

fromInfoWorld
2 months ago

Deno boosts dependency management with JSR

JSR offers a modern, TypeScript-first and cross-platform-compatible registry, integrated into Deno, Deno's developers said. For Node.js and NPM compatibility, Deno 1.42 offers numerous improvements. The async_hooks module now supports the EventEmitterAsyncResource and AsyncLocalStorage.enterWith APIs. The crypto module adds getRandomValues(), subtle, getCipherInfo(), publicKey(), and createPublicKey() APIs, along with support for more curves in multiple APIs. The worker_threads module received a major overhaul.
Node JS
Software development
fromMedium
1 year ago

How Bit Reduces Development Costs

A composable, well-documented codebase increases reuse, reduces bugs, and enables AI and non-technical stakeholders to contribute effectively.
Software development
fromZDNET
2 months ago

5 atomic Linux distros I trust for stress-free OS updates - and why

Atomic Linux distributions ensure upgrades either fully apply on reboot or are discarded, often adding immutability, containerized apps, and free availability.
Software development
fromTheregister
1 month ago

Debian 14 will drop Gtk2 - unless Ardour rides to the rescue

Debian 14 will remove Gtk2 support, affecting 139+ applications including FreePascal's Lazarus IDE, forcing projects to either migrate to Gtk3 or maintain their own toolkit forks.
Software development
fromDbmaestro
1 year ago

Why Do You Need Database Version Control?

Database version control tracks schema and code changes, enabling CI/CD integration, collaboration, rollback, and faster, more reliable deployments across multiple databases.
Software development
fromTheregister
2 months ago

Contain your Windows apps inside Linux Windows

Run real Windows inside an automatically managed Linux VM and export native Windows apps as individual windows integrated with the Linux desktop using RDP.
Software development
fromGitHub
2 months ago

GitHub - antonreshetov/bumpy: Zero-config, Git-powered versioning for monorepos

Bumpy provides zero-config, Git-driven versioning and changelog generation for monorepos, using workspace detection, Conventional Commits, tag-based boundaries, and dry-run support.
Software development
fromInfoQ
2 months ago

Rspack Releases Version 1.7: Final 1.x Update Before 2.0 Transition

Rspack 1.7 stabilizes features, improves SWC plugin compatibility, adds native Import Bytes support, and enables lazy compilation by default for dynamically imported modules.
fromTheregister
2 months ago

VS Code for Linux may be secretly hoarding trashed files

The reason for this is Snap - a Linux application packaging format - creates a local Trash folder for each VS Code version, one that's separate from the system-managed Trash, according to a VS Code bug report dating back to November 11, 2024. Not only that, but Snap keeps older versions of VS Code after updates, potentially multiplying the number of local Trash folders and the trashed-but-not-deleted files therein. Emptying the system Trash folder doesn't affect the local instances.
Software development
Software development
fromDbmaestro
4 years ago

Database delivery automation with GitLab: a deep dive |

Integrate databases into DevOps pipelines to eliminate bottlenecks, accelerate releases, and enable close collaboration between application and database teams.
[ Load more ]