Liran Tal
@lirantal.com
4K followers 440 following 2.4K posts
🦄 Node.js Secure Coding: http://nodejs-security.com 🌟 @GitHub Star 🏅 @OpenJS Pathfinder award for Security 🥑 DevRel at @snyksec
Posts Media Videos Starter Packs
OF COURSE
It's pretty silly metrics. I was posting for funs :D
Thanks but honestly this doesn't mean much :-)
I guess I'm top 1% JavaScript engineers globally, how is this even scored hah
if your npm access tokens page doesn't look like this then you are a walking supply chain security incident timebomb
damn Drizzle knows their target audience 10/10
using a model context protocol server to accelerate software development is such a huge hack

here's an example of using it with the new Nuxt 4 and Nuxt UI where I've added MCP servers for both.
I really dig it that Nuxt UI has its own dedicated MCP Server for LLM context and they also have an llms.txt file which is great ui.nuxt.com/docs/getting...
Cool write-up by DeveloperSteve on how they integrated Snyk into their AI agentic workflows via the Snyk CLI: blog.developersteve.com/how-i-integr...
who's asking for security testing best practices?? 👇
Reposted by Liran Tal
Un interessante guida per rendere più sicure le installazioni di pacchetti Node
yeah I don't remember
I think there was one by nodesource (there's npmdiff too)
is anyone using Deno and the secure-by-default permissions system and this saved them please raise your hand I want to chat and learn more

I appreciate Deno and Node.js (less comprehensive) for this but I'm unconvinced this helps against supply chain security attacks
2025 has been fun CVE wise for me ;-)
Gotcha yeah that works
Hah I get that way too often
By the way, on the same context of malicious packages - when the news break out and you need to obtain sources of the npm package (often already removed from npm) - where do you go to find it?