<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Npm on westerweel.work</title><link>https://westerweel.work/en/tags/npm/</link><description>Recent content in Npm on westerweel.work</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 18 May 2026 22:25:05 +0200</lastBuildDate><atom:link href="https://westerweel.work/en/tags/npm/index.xml" rel="self" type="application/rss+xml"/><item><title>Five config lines against supply-chain attacks (npm + PyPI)</title><link>https://westerweel.work/en/posts/2026-05-18-npm-supply-chain-cooldown/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://westerweel.work/en/posts/2026-05-18-npm-supply-chain-cooldown/</guid><description>npm yanks malicious versions within 24-48 hours; PyPI quarantines new uploads within hours. A seven-day cooldown — five config lines — turns that window into your defence.</description></item></channel></rss>