1. https://appdevelopermagazine.com/open-source
  2. https://appdevelopermagazine.com/npm@6-package-manager-brings-new-security-features/
4/25/2018 9:57:01 AM
npm@6 package manager brings new security features
npm@6,Javascript Developers
/npm-Update-2018-App-Developer-Magazine_m0t5mbmi.jpg
App Developer Magazine
npm@6 package manager brings new security features

Open Source

npm@6 package manager brings new security features


Wednesday, April 25, 2018

Austin Harris Austin Harris

npm announced the update of their JavaScript software installer tool in order to provide their users with improved security.

npm, Inc. has announced npm@6, a major update to its JavaScript software installer tool with new security features for developers who work with open source code. npm@6 will be included as part of the Node.js v10.x release line, and leverages the assets of the Node Security Platform, the definitive source of JavaScript vulnerabilities, recently acquired by npm, Inc.

In an npm, Inc. survey of over 16,000 worldwide developers, 97% of JavaScript developers confirm they use open source code, although 77% express concern about whether the open source software they use is secure, and 52% believe that there aren’t satisfactory methods for evaluating whether code is safe.

npm@6 brings protection against insecure code into the workflow that’s already used by 10 million JavaScript developers to download over 900 million packages of reusable, modular code per day.

These new protections include automatic warnings if a developer attempts to use open source code with known security issues, and `npm audit`, an npm command that allows developers to analyze complex, interdependent code to pinpoint specific vulnerabilities.

`npm audit` and insecure code warnings are available today to beta users and will roll out automatically to all users of npm@6 and the npm Registry over a period of weeks. The protections are free of charge to all users of the npm Registry with no required registration. In addition, customers of npm, Inc.’s paid offerings will receive pre-publication vulnerability disclosures, formerly a premium tier of the Node Security Platform product.

“Node.js has proven to be a reliable platform for applications at any scale. It is used across industries to build everything from APIs to cloud, mobile and IoT applications,” said Mark Hinkle, Executive Director of the Node.js Foundation. “The release of npm@6 is another great testament to the Node.js ecosystem’s focus and work on making security a top priority, and helping developers build the world’s most scalable, mission-critical JavaScript applications.”

When a user downloads code from the npm Registry, npm will review the request against the Node Security Platform database and return a warning if the code contains a vulnerability. In addition, the `npm audit` command within npm@6 will allow the developer to recursively analyze trees of dependent code to identify specifically what’s insecure. Typical packages can be analyzed in less than one second.

“Before npm security, people were just hoping for the best,” Adam Baldwin, Head of Security at npm, Inc. “Every developer needs to know that the code they use is safe. By alerting the entire npm community to security vulnerabilities within a tool they already use, we can make JavaScript development safer for everyone.”





Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


AI is becoming more widespread in collaboration tools
AI is becoming more widespread in collaboration tools Thursday, April 9, 2026




FCC prohibits new foreign router models citing critical infrastructure risks
FCC prohibits new foreign router models citing critical infrastructure risks Thursday, April 9, 2026


ChatGPT Carbon Footprint Matches 1.3 Million Cars Report Finds
ChatGPT Carbon Footprint Matches 1.3 Million Cars Report Finds Monday, April 6, 2026


Lens Launches MCP Server to Connect AI Coding Assistants with Kubernetes
Lens Launches MCP Server to Connect AI Coding Assistants with Kubernetes Tuesday, March 31, 2026


Accelerating corporate ai investment returns
Accelerating corporate ai investment returns Monday, March 30, 2026


Enviromates tech startup launches global participation platform
Enviromates tech startup launches global participation platform Friday, March 27, 2026


Private Repository Secures the AI-driven Development Boom
Private Repository Secures the AI-driven Development Boom Friday, March 27, 2026


UK Fintech Platform Enviromates Connects Projects Brands and Consumers
UK Fintech Platform Enviromates Connects Projects Brands and Consumers Thursday, March 26, 2026


Env Zero and CloudQuery Announce Merger
Env Zero and CloudQuery Announce Merger Thursday, March 26, 2026


How Industrial AI Is Transforming Operations in 2026
How Industrial AI Is Transforming Operations in 2026 Wednesday, March 25, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>