🧪 Tech & Open Source
npm Supply Chain Alerts
Community⏱ Every morning at 08:00
Every npm supply chain incident sends you grepping lockfiles to see if you're exposed, usually a day after everyone else. This watch screens each new malicious-package advisory against the dependencies you name, so you hear about compromised versions while a pin or rollback still helps.
- Suggested cadence
- Every morning at 08:00
- Typically watches
- GitHub Security Advisories · Socket.dev blog · Snyk vulnerability DB · npm blog
- Tags
- npm · supply-chain · security · javascript
The prompt
I maintain the frontend platform at a Toronto fintech with roughly 40 direct npm dependencies, including axios, lodash, next, zod, and tanstack-query. Alert me on any malicious package advisory, compromised maintainer account, or typosquat targeting those packages or their popular transitive dependencies. Must include the affected version range and the safe version to pin. Postinstall-script malware anywhere in the top 500 npm packages is worth a heads-up too. I don't care about ordinary license or deprecation notices.
This is the whole template — the words the wizard analyzes into sources, filters, and a schedule. You review and edit every step before the watch runs.
More like this
Critical CVEs in My StackOfficial
Know within hours when a critical CVE lands in something you actually run.
I run Node.js 22, PostgreSQL 16, nginx 1.26, and Ubuntu 24.04 in production. Alert me on any new CVE affecting those exact components with a CVSS score of 8.0 or higher, or anything added to the CISA KEV list regardless of score. Every alert must name the affected version range and the patched version or a workaround. A public proof-of-concept exploit makes it urgent, flag that separately. Ignore advisories for components I don't run.
⏱ Every 2 hours
Frontier Model LaunchesOfficial
Every new frontier model with pricing and context window, the day it ships.
I build LLM products and need to know about every new model release from OpenAI, Anthropic, Google DeepMind, Meta, and Mistral. Must include the API pricing per million tokens and a context window of at least 128k, otherwise it's not relevant to my work. Open-weights releases are a bonus and so are published benchmark comparisons against the previous generation. Skip minor version bumps and region-only rollouts.
⏱ Twice a day
React and Next.js Upgrade RadarOfficial
Breaking changes and codemods for your React stack, before you hit them in CI.
My remote product team maintains four apps on Next.js 15 and React 19 with the App Router. Alert me on every new stable major or minor release of React or Next.js that includes breaking changes, deprecations, or changed defaults. Each alert must summarize what breaks and whether an official codemod covers it. RFCs that affect the App Router or Server Components are a bonus. Ignore canary and experimental releases entirely.
⏱ Weekly digest, Mondays