Safe-NPM
only install packages that are +90 days old
Details
- External ID
- 46027878
- Source
- HN
- Company
- —
- Product
- Safe-NPM
- Website domain
- github.com
- Launched
- Nov. 23, 2025
- Cohort
- —
- Upvotes
- 90
- Upvotes percentile
- 0.9017467248908297
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
This past quarter has been awash with sophisticated npm supply chain attacks like [Shai-Hulud](https://www.cisa.gov/news-events/alerts/2025/09/23/widesprea...() and the [Chalk/debug Compromise](https://www.wiz.io/blog/widespread-npm-supply-chain-attack-b...). This CLI helps protect users from recently compromised packages by only downloading packages that have been public for a while (default is 90 days or older).Install: npm install -g @dendronhq/safe-npm Usage: safe-npm install react@^18 lodashHow it works: - Queries npm registry for all versions matching your semver range - Filters out anything published in the last 90 days - Installs the newest "aged" versionLimitations: - Won't protect against packages malicious from day one - Doesn't control transitive dependencies (yet - looking into overrides) - Delays access to legitimate new featuresThis is meant as a 80/20 measure against recently compromised NPM packages and is not a silver bullet. Please give it a try and let me know if you have feedback.
Enrichment
- Theme
- security exploits and system hacking tools
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- npm package security filter for developers
- Manually corrected
- False
Could you build this?
Yes It is a straightforward CLI tool that wraps npm install or checks package release dates against the npm registry API before installing.
Discussion
20 comments analyzed.
Competitors mentioned: pnpm, yarn, Debian package manager, Renovate
Concerns raised: NPM ecosystem has too many packages to safely maintain, Recent security issues decrease trust in npm, npm install can upgrade versions unexpectedly despite lockfiles, Malicious packages exploit effectiveness unclear, Minimal age gate becomes less useful if widely adopted
Feature requests: npm should be stable mainline with advantages of pnpm/yarn, TypeScript website should mention Debian package availability, Use exact version pinning instead of semver ranges by default
Competitors
Other products that read as similar to this one — 52 launches clear the similarity bar, closest 8 shown.
Attention rank: #6 of 53 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 3 days after the earliest competitor.
- Safe-install · hn · 2026-05-12 · 19 upvotes · similarity 0.63
- Auto-Unpublish NPM Packages Published Outside CI · hn · 2025-11-27 · 6 upvotes · similarity 0.48
- DepsGuard · hn · 2026-06-01 · 40 upvotes · similarity 0.47
- npm Package Inspector · ph · 2026-09-21 · 2 upvotes · similarity 0.46
- FixMyNPM, CLI to fix your insecure npm config · hn · 2026-05-13 · 10 upvotes · similarity 0.46
- OSS sustain guard · hn · 2026-01-05 · 21 upvotes · similarity 0.37
- Repogen · hn · 2026-01-06 · 38 upvotes · similarity 0.37
- Cossistant · hn · 2025-11-21 · 6 upvotes · similarity 0.37
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.