The Changelog: Software Development, Open Source
The Changelog: Software Development, Open Source
Changelog Media
Securing npm is table stakes (Interview)
1 hour 21 minutes Posted Jan 29, 2026 at 3:00 pm.
Welcome to The Changelog
Sponsor: Tiger Data
Start the show!
Recent npm history
GitHub's response
Trusted publishing
What makes it trusted
What they're not doing
Sponsor: Namespace
Misaligned incentives
One big attack away
How staffed is npm?
Is using npm still prudent?
Pre/post install hooks
Verified publishers
Sponsor: Squarespace
JSR and vlt
An Anthropic registry
How other ecosystems do it
The cool factor
The profit incentive
Nicholas' work
Connecting with Nicholas
AI: not just hype
Wrapping up
Closing thoughts
0:00
1:21:11
Download MP3
Show notes
As the creator and long-time maintainer of ESLint, Nicholas Zakas is well-positioned to criticize GitHub's recent response to npm's insecurity. He found the response insufficient, and has other ideas on how GitHub could secure npm better. On this episode, Nicholas details these ideas, paints a bleak picture of npm alternatives like JSR, and shares our frustration that such a critical piece of internet infrastructure feels neglected.