More The Changelog: Software Development, Open Source episodes

Securing npm is table stakes (Interview) thumbnail

Securing npm is table stakes (Interview)

Published 29 Jan 2026

Duration: 1:21:11

Security concerns in the NPM registry, including credential theft and malicious package publication, are being addressed through discussions on governance, community involvement, and alternative registries, amidst challenges in abandoning the widely used ecosystem.

Episode Description

As the creator and long-time maintainer of ESLint, Nicholas Zakas is well-positioned to criticize GitHub's recent response to npm's insecurity. He fou...

Overview

The podcast addresses ongoing security concerns within the NPM ecosystem, focusing on issues like credential theft and the publication of malicious packages that can execute harmful code via pre-install or post-install scripts. These vulnerabilities pose significant risks to developers and organizations relying on NPM for their JavaScript dependencies. Nicholas Zakis, a security expert, criticizes the current response from NPM and GitHub, arguing that the measures in place are inadequate and that neither platform has been proactive in addressing these security challenges.

The discussion highlights the uncertainty around NPM's long-term security and maintenance, pointing to problems such as poor token management and the absence of two-factor authentication for trusted publishing. Additionally, the risks of malicious pull requests in widely used open source projects are mentioned as a contributing factor to the overall insecurity. While alternatives like JSR and Volt are noted, they are deemed insufficient in terms of adoption and effectiveness. The need for stronger governance within NPM is emphasized, such as imposing restrictions on dangerous scripts and considering a transition to a community-run foundation to ensure a more sustainable and secure model. Lastly, the challenges of moving away from NPM are acknowledged due to its vast user base and extensive package ecosystem, reinforcing the importance of improving trust and security within the open source community.

Recent Episodes of The Changelog: Software Development, Open Source

3 Sept 2026 Forking Cal.com to closed source (Interview)

"AI-generated code floods open source projects, obscuring vulnerabilities and overwhelming maintainers, prompting shifts to private repositories and cloud-based development as security risks escalate."

25 Aug 2026 Postgres at PlanetScale (Interview)

"PlanetScale launched a $5 PostgreSQL plan, detailed metal deployment for performance, previewed sharded PostgreSQL product Niki, and discussed AI workloads, CI/CD challenges, and engineering-driven scaling strategies."

21 Jul 2026 Canary tokens and digital tripwires (Interview)

"Thinkst, a 50-person cybersecurity firm, specializes in Canary honeypots and Canary Tokens, offering simple, no-maintenance detection tools with $22.5M ARR, no price hikes in a decade, and AI-driven threat awareness."

5 Jun 2026 From open source hits to OpenAI (Interview)

A deep dive into open source contributions, AI-driven developer roles, challenges in maintaining projects like Spectrum and GitHub's acquisitions, balancing altruistic work with career growth, technical topics such as GraphQL and database scalability, and the evolving landscape of cloud environments and plugin ecosystems.

15 May 2026 MCP on Code Mode (Interview)

The Field CTO role focuses on data-driven product alignment with customer needs, advocating secure cloud environments, the Model Context Protocol for agent interactions, and balancing automation with security in AI-driven development workflows.

More The Changelog: Software Development, Open Source episodes