Is the npm xlsx Package Safe? A Security Review
A security review of the npm xlsx (SheetJS) package: its prototype pollution and ReDoS CVEs, the npm-versus-CDN patch gap, and how to install it safely.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
A security review of the npm xlsx (SheetJS) package: its prototype pollution and ReDoS CVEs, the npm-versus-CDN patch gap, and how to install it safely.
npm-force-resolutions pins vulnerable transitive dependencies to safe versions on older npm. Here is how it works, its risks, and why native npm overrides now beat it.
npm pack builds the exact tarball that would be published to the registry. Using it before every publish is the simplest way to avoid shipping secrets.
react-oidc-context wraps oidc-client-ts in React hooks for SPA authentication. Here is how to wire it up without leaking tokens or trusting the wrong callback.
This Babel plugin is deprecated, not vulnerable. The real risk is supply chain hygiene: depending on an unmaintained package when the standard replacement is a one-line swap.
react-native-background-upload moves files while your app is backgrounded, which is exactly why its security depends on how you handle URLs, tokens, and native permissions.
The webpack latest version sits in the 5.x line and updates frequently. Here is how to check which version you run, why staying current matters for security, and how to upgrade safely.
cross-fetch still ships in thousands of lockfiles as a universal fetch polyfill. A review of its one CVE, its node-fetch dependency, and when you no longer need it.
The react-native-google-places-autocomplete component makes location search easy, but it can also leak your Google API key straight out of a shipped app. Here's how to use it safely.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.