Node Weekly Issue 627 covers several topics: replacements.fyi, a tool for finding lighter npm package alternatives or native Node.js APIs; supply chain attack news targeting Red Hat packages and a worm hiding in binding.gyp files; Node.js Interactive returning at RenderATL 2026 in Atlanta; VoidZero (behind Vite, Vitest, Rolldown, Oxc) joining Cloudflare; and a multiparty 4.3.0 security release fixing three DoS vulnerabilities. Also featured is a guide on how to evaluate npm packages before installing, covering provenance attestation, install scripts, and CI quality.
402 Impressions