NPM Security & Versioning: How to Keep Your Packages SAFE!

NPM Security & Versioning: How to Keep Your Packages SAFE!

Feb 3, 2025

Use Snyk for free to find and fix security issues in your applications today! https://snyk.co/ugLYn

In this video, we will be stepping through how to do security checks for your npm package as well as version management and publishing.

Check out Part 2 here → https://youtu.be/jaKmqGxDSxQ

Read more about how to build an npm package for ESM and CJS in our related blog: https://snyk.co/ugXDj

✍️ Resources ✍️

⏲️ Chapters ⏲️

00:00 - Intro

00:28 - Adding security checks with Snyk

04:20 - What is semantic versioning?

05:35 - Getting set up with semantic release

08:28 - How to get an npm access token

10:36 - Dry run test

12:37 - Creating a new workflow for the repository

16:16 - What are conventional commits?

17:30 - Free continuous monitoring with Snyk

19:22 - Outro

⚒️ About Snyk ⚒️

Snyk helps you find and fix vulnerabilities in your code, open-source dependencies, containers, infrastructure-as-code, software pipelines, IDEs, and more! Move fast, stay secure.

Learn more about Snyk: https://snyk.co/ugLYl

📱 Connect with Us 📱

🖥️ Website: https://snyk.co/ugLYl
🐦 X: http://twitter.com/snyksec
💼 LinkedIn: https://www.linkedin.com/company/snyk
💬 Discord: https://discord.gg/devsecops-community-918181751526948884

🔗 Hashtags 🔗
#npm #package #snyk #code #coding #cybersecurity #software #security #practice #development #developer #application #vulnerabilities #environments #deployment #published #testing #build #guide #tutorial #productionready #productiontest #codetests #npmtests