{"adoption": {"forks": 42, "observed_at": "2026-08-28T04:04:07.685804+00:00", "stars": 1248}, "canonical_url": "https://ross.abutalabs.com/products/npm-security-best-practices", "card": {"archived": false, "artifact_type": "learning-resource", "description": "Collection of npm package manager Security Best Practices", "domain": ["security", "developer-tools", "awesome-lists", "web-development"], "enriched": true, "function": ["security", "developer-tools", "documentation"], "health_score": 70, "homepage": null, "language": null, "license": "Apache-2.0", "license_family": "permissive", "maturity": "active", "member_repos": ["lirantal/npm-security-best-practices"], "name": "lirantal/npm-security-best-practices", "platform": ["cli"], "pushed_at": "2026-05-24T18:40:02+00:00", "repo": "lirantal/npm-security-best-practices", "stars": 1248, "tags": ["npm", "supply-chain-security", "best-practices", "awesome-list", "pnpm", "bun", "package-manager-security", "shai-hulud", "nodejs"], "topics": ["awesome", "awesome-list", "best-practices", "nodejs", "npm", "security", "supply-chain-security", "vulnerabilities", "shai-hulud", "shai-hulud-attack", "shai-hulud-detector"], "urls": [], "use_cases": ["harden npm against supply chain attacks", "disable postinstall scripts safely", "block recently published npm packages", "secure .npmrc configuration examples", "mitigate shai-hulud style npm compromises", "vet npm package dependencies for security", "configure pnpm security settings"], "what_it_is": "A curated awesome-list of npm package manager security best practices, covering safe-by-default CLI options, supply chain attack hardening, and secure dependency resolution. It includes copy-paste secure configurations for npm, pnpm, and bun package managers.", "when_to_avoid": ["you need an automated security scanning tool rather than guidance", "you are not using npm, pnpm, or bun as your package manager"], "when_to_choose": ["you maintain Node.js projects and want to reduce npm supply chain risk", "you need practical, copy-paste package manager security configs", "you want a curated reference of npm security practices"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/npm-security-best-practices", "repo": "lirantal/npm-security-best-practices", "role": "main", "score": 55}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:07.685804+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T05:07:53.537231+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b4a024058bf123fcfcb03ce44b3da98c4e0cf612ca18ac1b9b463b025326b5f3", "fetched_at": "2026-08-28T04:04:07.685804+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lirantal/npm-security-best-practices"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 84, "longevity": 23, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 335, "days_push": 101, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 55, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}