A weekly roundup of package management news covering security fixes, releases, and articles. Key security items include npm invalidating granular access tokens that bypassed 2FA, npm 11.16.0 introducing an allowScripts install policy, pnpm 10.34.0/11.4.0 hardening tarball integrity and credential scoping, NuGet.Server 3.4.3 fixing a DoS on the upload endpoint, Cargo 1.96 patching two CVEs for third-party registries, and Composer 2.10 shipping native malware filtering. On the releases side: pnpm 11.3.0 adds staged publishing support, winget 1.29.240 lands as an RC, dependabot-core 0.378.0 adds blocked-versions support, and pixi 0.69.0 gets browser-based OAuth. Articles cover curl project pressures, cargo-semver-checks 2026 plans, LLM-generated Python library reimplementations, and Python wheel-next packaging PEPs.

5m read timeFrom nesbitt.io
Post cover image
Table of contents
Security #Releases #Articles #Elsewhere #git-pkgs #
175 Impressions