Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Safe-NPM

only install packages that are +90 days old

Details

External ID
46027878
Source
HN
Company
—
Product
Safe-NPM
Website domain
github.com
Launched
Nov. 23, 2025
Cohort
—
Upvotes
90
Upvotes percentile
0.9017467248908297
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

This past quarter has been awash with sophisticated npm supply chain attacks like [Shai-Hulud](https://www.cisa.gov/news-events/alerts/2025/09/23/widesprea...() and the [Chalk/debug Compromise](https://www.wiz.io/blog/widespread-npm-supply-chain-attack-b...). This CLI helps protect users from recently compromised packages by only downloading packages that have been public for a while (default is 90 days or older).Install: npm install -g @dendronhq/safe-npm Usage: safe-npm install react@^18 lodashHow it works: - Queries npm registry for all versions matching your semver range - Filters out anything published in the last 90 days - Installs the newest "aged" versionLimitations: - Won't protect against packages malicious from day one - Doesn't control transitive dependencies (yet - looking into overrides) - Delays access to legitimate new featuresThis is meant as a 80/20 measure against recently compromised NPM packages and is not a silver bullet. Please give it a try and let me know if you have feedback.

Enrichment

Theme
security exploits and system hacking tools
Vertical
Security
Function
Compliance & governance
Audience
Developer
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
npm package security filter for developers
Manually corrected
False

Could you build this?

Yes It is a straightforward CLI tool that wraps npm install or checks package release dates against the npm registry API before installing.

Discussion

20 comments analyzed.

Competitors mentioned: pnpm, yarn, Debian package manager, Renovate

Concerns raised: NPM ecosystem has too many packages to safely maintain, Recent security issues decrease trust in npm, npm install can upgrade versions unexpectedly despite lockfiles, Malicious packages exploit effectiveness unclear, Minimal age gate becomes less useful if widely adopted

Feature requests: npm should be stable mainline with advantages of pnpm/yarn, TypeScript website should mention Debian package availability, Use exact version pinning instead of semver ranges by default

Competitors

Other products that read as similar to this one — 52 launches clear the similarity bar, closest 8 shown.

Attention rank: #6 of 53 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 3 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.