• N|Solid
    • Overview
    • Observability
    • Security
    • AI
    • OSS Runtime
    • DevTools
  • Node.js
    • Services
    • Support
    • Training
    • Upgrade
    • Distributions
  • Solutions
    • API Integration / Microservices
    • High Performance Applications
    • Legacy Application Migration
    • Internet of Things
  • Resources
    • Blog
    • N|Solid Docs
    • Knowledge Center
    • Partner Program
    • Infrastructure Cost
  • Company
    • Contact Us
    • About
    • Press
BOOK A DEMO
SIGN IN/SIGN UPCONTACT US
  • N|Solid
    • Overview
    • Observability
    • Security
    • AI
    • OSS Runtime
    • DevTools
  • Node.js
    • Services
    • Support
    • Training
    • Upgrade
    • Distributions
  • Solutions
    • API Integration / Microservices
    • High Performance Applications
    • Legacy Application Migration
    • Internet of Things
  • Resources
    • Blog
    • N|Solid Docs
    • Knowledge Center
    • Partner Program
    • Infrastructure Cost
  • Company
    • Contact Us
    • About
    • Press
BOOK A DEMO
SIGN IN/SIGN UP

The NodeSource Blog

All Posts

Security

npm-v12-blocks-install-scripts-why-youre-not-safe-yet

npm v12 Blocks Install Scripts. So Why Aren't You Safe Yet?

In Community  on Aug 14 2026

npm v12 blocks automatic install scripts, but supply chain risks remain. Learn why runtime execution still matters for Node.js security.

Read More

why-npm-install-can-execute-code-npm-v12

Why Installing an npm Package Can Execute Code on Your Machine (And Why npm v12 Finally Changes That)

In Community  on Aug 02 2026

Learn how npm install scripts can execute code on your machine, the security risks they create, and what changes with npm v12.

Read More

nodejs-hackerone-signal-requirement

Understanding Node.js’ New Signal Requirement for Security Reports

In Node.js  on Feb 05 2026

Node.js introduced a Signal requirement on HackerOne to reduce noise, improve vulnerability report quality, and support security maintainers.

Read More

cve-vs-cvss-explained-security-vulnerabilities

CVE, CVSS, and the Mistake Most Teams Keep Making

In Security  on Jan 21 2026

Learn what CVE and CVSS really mean, how they differ, and how to use them correctly to prioritize security vulnerabilities in real-world systems.

Read More

nodejs-security-release-january-2026

Node.js January 2026 Security Release: What Changed and Why It Matters

In Node.js  on Jan 14 2026

Learn what changed in the Node.js January 2026 security release, which CVEs affect you, and how to assess impact and upgrade safely in production

Read More

1 / 1

Featured Articles

  • Owning the Agentic SDLC: How NodeSource Reclaimed Control of AI Development

    In ai  on Aug 12 2026

  • 2 Million Runtime Downloads: Thank You for Trusting N|Solid

    In NodeSource  on Jul 16 2026

  • Introducing the N|Solid Plugin for AI Coding Agents

    In ai  on Jul 08 2026

Categories

  • ai
  • Community
  • Debugging
  • How To
  • newsletter
  • Node.js
  • Node.js
  • NodeSource
  • Observability
  • Product
  • Security
  • Upgrade Program

© 2026 NodeSource

  • What We Do
  • N|Solid
  • Product Pricing
  • NodeSource Services
  • Solutions
  • Microservices
  • High Traffic
  • Legacy Applications
  • Internet of Things
  • Learn
  • Blog
  • Resources
  • Support Portal
  • Documentation
  • Company
  • Contact Us
  • About NodeSource
  • Press
  • Legal
  • Privacy Policy