Writing··9 min read
What I Learned Auditing 10,000 npm Packages
Supply chain risks, phantom dependencies, and why install scripts remain JavaScript's largest security blind spot.
#Security#Node.js#Open Source
“Ideas, experiments, documentation and things I cannot stop thinking about.”
Supply chain risks, phantom dependencies, and why install scripts remain JavaScript's largest security blind spot.
Testing multimodal models on complex editorial typography, asymmetric grids, and responsive layouts.
Complete technical reference, installation guide, AST heuristics, and CI/CD integration.
A retrospective on what happens when speculation outpaces actual software utility.
When generating code costs zero effort, the cost of understanding it approaches infinity.