
technologyJan 29, 20261:21:11pending
Securing npm is table stakes (Interview)
About this episode
As the creator and long-time maintainer of ESLint, Nicholas Zakas is well-positioned to criticize GitHub's recent response to npm's insecurity. He found the response insufficient, and has other ideas on how GitHub could secure npm better. On this episode, Nicholas details these ideas, paints a bleak picture of npm alternatives like JSR, and shares our frustration that such a critical piece of internet infrastructure feels neglected.
Get every episode summarized
Each time The Changelog: Software Development, Open Source publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Changelog: Software Development, Open Source

Forking Cal.com to closed source (Interview)
The Changelog: Software Development, Open Source
Sep 3, 20261:54:32completed

Postgres at PlanetScale (Interview)
The Changelog: Software Development, Open Source
Aug 25, 20261:42:17pending

Canary tokens and digital tripwires (Interview)
The Changelog: Software Development, Open Source
Jul 21, 20262:06:48pending

From open source hits to OpenAI (Interview)
The Changelog: Software Development, Open Source
Jun 5, 20261:46:28pending