My new article is out! A systematic guide to releasing npm packages as safely as possible in 2026 (with a Skill to quickly apply the practices to your open source projects). Not just “do X”: I cover real supply chain attacks and explain how each defense helps. evilmartians.com/chronicles/t...
The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog
How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings
evilmartians.com