frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: npm-daycare, an NPM proxy that filters out recent & small packages

https://github.com/stack-auth/npm-daycare
5•n2d4•1h ago
Hey all! npm-daycare is a simple NPM proxy built on Verdaccio which filters all packages that:

- are younger than 48h (it will just provide an old version instead)

- have fewer than 5,000 weekly downloads

https://github.com/stack-auth/npm-daycare

This is in response to the recent supply chain attacks that shattered the JavaScript ecosystem [1]. It's likely not a problem that will go away any time soon, so we figured we'd build something to protect against it.

Doing this on the proxy layer means it will work across the entire system, as proxies are set globally. In the future, we could also add more filters to the proxy.

To get started, just run the Docker container:

    docker run -d --rm --name npm-daycare -p 4873:4873 bgodil/npm-daycare

    npm set registry http://localhost:4873/
    pnpm config set registry http://localhost:4873/
    yarn config set registry http://localhost:4873/
    bun config set registry http://localhost:4873/

    npm view @types/node  # has recent updates
    npm view pgmock  # has <5,000 weekly downloads

Downside: npm-daycare won't show packages that are younger than 48h on its default config, so be aware of that when you try to update your packages to patch a zero-day exploit.

You probably also shouldn't rely on this as your only line of defense. Curious to hear what you think!

[1] https://news.ycombinator.com/item?id=45260741

Comments

bdangubic•8m ago
Day is September 16, 2026. Top story on HN, “wildly popular npm-daycare with 7 billion daily downloads hacked” :-)

Show HN: HuMo AI – Create Realistic Videos with Text, Image, and Audio Inputs

https://www.humoai.co
1•Viaya•30s ago•0 comments

Yay! Yogis Can Fly! (2004)

https://www.vice.com/en/article/yay-v11n4/
1•TMWNN•1m ago•0 comments

Show HN: Simple sandboxed way to install and run Node.js scripts using Docker

1•freakynit•2m ago•0 comments

Java 25 General Availability

https://jdk.java.net/25/
1•za3faran•3m ago•0 comments

Cigarette Filter

https://en.wikipedia.org/wiki/Cigarette_filter
1•thunderbong•7m ago•0 comments

Read-through cache for object storage

https://github.com/s2-streamstore/cachey
1•shikhar•13m ago•0 comments

An efficient and user-friendly hybrid cache lib in Rust

https://github.com/foyer-rs/foyer
2•gangtao•13m ago•0 comments

Starfront Observatories

https://starfront.space/
2•stefanpie•15m ago•0 comments

How many parameters could a $100B datacenter train? [pdf]

https://conferences.sigcomm.org/hotnets/2024/papers/hotnets24-333.pdf
1•halation_effect•17m ago•0 comments

Phota Labs: personalized genAI photography, raises $5.6M led by A16Z

https://twitter.com/PhotaLabs/status/1967985593046143382
2•talos•24m ago•1 comments

Reworking Memory Management in CRuby

https://railsatscale.com/2025-09-16-reworking-memory-management-in-cruby/
2•doppp•33m ago•0 comments

Show HN: A PSX/DOS style 3D game written in Rust with a custom software renderer

https://totenarctanz.itch.io/a-scavenging-trip
6•mvx64•35m ago•0 comments

Global Peace Index 2025

https://www.visionofhumanity.org/maps/
18•teleforce•37m ago•4 comments

The better you play, the more colorful it gets

https://musicolour.art/
2•gdss•38m ago•1 comments

Pinterest co-founder Evan Sharp on his new company West Co

https://designerfounders.substack.com/p/evan-sharp-pinterest-west
1•rbnpark•38m ago•0 comments

Ants Found a Loophole for a Fundamental Rule of Life

https://www.nytimes.com/2025/09/15/science/ants-species-babies.html
1•andsoitis•40m ago•0 comments

Why are so many Americans moving to Portugal

https://www.theguardian.com/world/2025/sep/16/why-are-so-many-americans-moving-to-portugal-apart-...
3•teleforce•42m ago•0 comments

EPA delay threatens fenceline communities near steel and coke plants

https://www.thenewlede.org/2025/08/steel-plants-fenceline-air-pollution-epa-rules/
3•PaulHoule•49m ago•0 comments

The Rise of De Novo Genes: From Scratch to Survival

https://www.the-scientist.com/the-rise-of-de-novo-genes-from-scratch-to-survival-73361
2•bookofjoe•50m ago•0 comments

Hyperion: Minecraft game engine for custom events

https://hyperion.rs/
2•cjcuddy•51m ago•0 comments

A Survey on Retrieval and Structuring Augmented Generation with LLMs

https://arxiv.org/abs/2509.10697
2•simonpure•53m ago•0 comments

Show HN: I built a tool to translate Chinese, Japanese, & Korean Novels

https://noveltranslator.com
1•yamii•55m ago•1 comments

The Mozilla Museum

https://home.snafu.de/tilman/mozilla/
1•nvr219•55m ago•0 comments

The Living Ink

https://substack.com/home/post/p-173814212
2•lout332•58m ago•0 comments

How to Use AI Without Becoming Stupid

https://commoncog.com/how-to-use-ai-without-becoming-stupid/
2•nsoonhui•1h ago•0 comments

Ongoing Supply Chain Attack Targets CrowdStrike NPM Packages

https://socket.dev/blog/ongoing-supply-chain-attack-targets-crowdstrike-npm-packages
6•TheCleric•1h ago•1 comments

Show HN: Users Loop – SaaS feedback, roadmaps and helpdesks

https://usersloop.com
1•awcode•1h ago•2 comments

Slow Social Media

https://herman.bearblog.dev/slow-social-media/
8•rishikeshs•1h ago•2 comments

Strawman Fallacy

https://en.wikipedia.org/wiki/Straw_man
2•chynkm•1h ago•0 comments

I got the highest score on ARC-AGI again swapping Python for English

https://jeremyberman.substack.com/p/how-i-got-the-highest-score-on-arc-agi-again
4•freediver•1h ago•0 comments