<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Sat, 04 Apr 2026 20:30:40 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>The Manifest - Episodes Tagged with “Npm”</title>
    <link>https://manifest.fm/tags/npm</link>
    <pubDate>Mon, 11 Dec 2017 06:00:00 +0000</pubDate>
    <description>Welcome to The Manifest, a podcast all about package management. Your hosts are Alex Pounds and Andrew Nesbitt. Together they explore the technical details of package management, the stories and the history of various projects, and the communities around them too. Every so often there will be a brand new interview with a package manager maintainer.
</description>
    <language>en-gb</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A podcast all about package management</itunes:subtitle>
    <itunes:author>Andrew Nesbitt and Alex Pounds</itunes:author>
    <itunes:summary>Welcome to The Manifest, a podcast all about package management. Your hosts are Alex Pounds and Andrew Nesbitt. Together they explore the technical details of package management, the stories and the history of various projects, and the communities around them too. Every so often there will be a brand new interview with a package manager maintainer.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/0/09b1672e-d238-4955-847b-084d98d93e95/cover.jpg?v=1"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>package management, podcast, software, open source</itunes:keywords>
    <itunes:owner>
      <itunes:name>Andrew Nesbitt and Alex Pounds</itunes:name>
      <itunes:email>andrew@manifest.fm</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>Episode 9: Typosquatting with Adam Baldwin</title>
  <link>http://manifest.fm/9</link>
  <guid isPermaLink="false">817f7709-f785-40d9-968e-527d89333095</guid>
  <pubDate>Mon, 11 Dec 2017 06:00:00 +0000</pubDate>
  <author>Andrew Nesbitt and Alex Pounds</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/09b1672e-d238-4955-847b-084d98d93e95/817f7709-f785-40d9-968e-527d89333095.mp3" length="27109626" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Andrew Nesbitt and Alex Pounds</itunes:author>
  <itunes:subtitle>Wherein we discuss typosquatting and other security matters with Adam Baldwin, of Lift security and the Node Security Platform.</itunes:subtitle>
  <itunes:duration>50:30</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/0/09b1672e-d238-4955-847b-084d98d93e95/cover.jpg?v=1"/>
  <description>Wherein we discuss typosquatting and other security matters with Adam Baldwin, of Lift security and the Node Security Platform. We cover what kind of exploits people are trying, speculate about how blockchains may well be the answer, and unsuccessfully attempt to start a turf war between various package managers.  Special Guest: Adam Baldwin.
</description>
  <content:encoded>
    <![CDATA[<p>Wherein we discuss typosquatting and other security matters with Adam Baldwin, of Lift security and the Node Security Platform. We cover what kind of exploits people are trying, speculate about how blockchains may well be the answer, and unsuccessfully attempt to start a turf war between various package managers. </p><p>Special Guest: Adam Baldwin.</p><p>Links:</p><ul><li><a title="^Lift Security" rel="nofollow" href="https://liftsecurity.io/">^Lift Security</a></li><li><a title="npm registry" rel="nofollow" href="https://www.npmjs.com/">npm registry</a></li><li><a title="Typo.js on GitHub" rel="nofollow" href="https://github.com/cfinke/Typo.js/">Typo.js on GitHub</a></li><li><a title="52% of All JavaScript npm Packages Could Have Been Hacked via Weak Credentials" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/52-percent-of-all-javascript-npm-packages-could-have-been-hacked-via-weak-credentials/">52% of All JavaScript npm Packages Could Have Been Hacked via Weak Credentials</a></li><li><a title="Have I been pwned?" rel="nofollow" href="https://haveibeenpwned.com/">Have I been pwned?</a></li><li><a title="Protect your npm account with two-factor authentication" rel="nofollow" href="http://blog.npmjs.org/post/166039777883/protect-your-npm-account-with-two-factor">Protect your npm account with two-factor authentication</a></li><li><a title="Typosquatting programming language package managers" rel="nofollow" href="http://incolumitas.com/2016/06/08/typosquatting-package-managers/">Typosquatting programming language package managers</a></li><li><a title="Shellshock" rel="nofollow" href="https://en.wikipedia.org/wiki/Shellshock_(software_bug)">Shellshock</a></li><li><a title="Dependency CI" rel="nofollow" href="https://dependencyci.com/">Dependency CI</a></li><li><a title="The Update Framework" rel="nofollow" href="https://theupdateframework.github.io/">The Update Framework</a></li><li><a title="package.community" rel="nofollow" href="http://package.community/">package.community</a></li><li><a title="crossenv malware on the npm registry" rel="nofollow" href="http://blog.npmjs.org/post/163723642530/crossenv-malware-on-the-npm-registry">crossenv malware on the npm registry</a></li><li><a title="Node Security Platform" rel="nofollow" href="https://nodesecurity.io/">Node Security Platform</a></li><li><a title="Yarn" rel="nofollow" href="https://yarnpkg.com/">Yarn</a></li><li><a title="Adam Baldwin on Twitter" rel="nofollow" href="https://twitter.com/adam_baldwin">Adam Baldwin on Twitter</a></li><li><a title="Adam Baldwin on GitHub" rel="nofollow" href="https://github.com/evilpacket">Adam Baldwin on GitHub</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Wherein we discuss typosquatting and other security matters with Adam Baldwin, of Lift security and the Node Security Platform. We cover what kind of exploits people are trying, speculate about how blockchains may well be the answer, and unsuccessfully attempt to start a turf war between various package managers. </p><p>Special Guest: Adam Baldwin.</p><p>Links:</p><ul><li><a title="^Lift Security" rel="nofollow" href="https://liftsecurity.io/">^Lift Security</a></li><li><a title="npm registry" rel="nofollow" href="https://www.npmjs.com/">npm registry</a></li><li><a title="Typo.js on GitHub" rel="nofollow" href="https://github.com/cfinke/Typo.js/">Typo.js on GitHub</a></li><li><a title="52% of All JavaScript npm Packages Could Have Been Hacked via Weak Credentials" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/52-percent-of-all-javascript-npm-packages-could-have-been-hacked-via-weak-credentials/">52% of All JavaScript npm Packages Could Have Been Hacked via Weak Credentials</a></li><li><a title="Have I been pwned?" rel="nofollow" href="https://haveibeenpwned.com/">Have I been pwned?</a></li><li><a title="Protect your npm account with two-factor authentication" rel="nofollow" href="http://blog.npmjs.org/post/166039777883/protect-your-npm-account-with-two-factor">Protect your npm account with two-factor authentication</a></li><li><a title="Typosquatting programming language package managers" rel="nofollow" href="http://incolumitas.com/2016/06/08/typosquatting-package-managers/">Typosquatting programming language package managers</a></li><li><a title="Shellshock" rel="nofollow" href="https://en.wikipedia.org/wiki/Shellshock_(software_bug)">Shellshock</a></li><li><a title="Dependency CI" rel="nofollow" href="https://dependencyci.com/">Dependency CI</a></li><li><a title="The Update Framework" rel="nofollow" href="https://theupdateframework.github.io/">The Update Framework</a></li><li><a title="package.community" rel="nofollow" href="http://package.community/">package.community</a></li><li><a title="crossenv malware on the npm registry" rel="nofollow" href="http://blog.npmjs.org/post/163723642530/crossenv-malware-on-the-npm-registry">crossenv malware on the npm registry</a></li><li><a title="Node Security Platform" rel="nofollow" href="https://nodesecurity.io/">Node Security Platform</a></li><li><a title="Yarn" rel="nofollow" href="https://yarnpkg.com/">Yarn</a></li><li><a title="Adam Baldwin on Twitter" rel="nofollow" href="https://twitter.com/adam_baldwin">Adam Baldwin on Twitter</a></li><li><a title="Adam Baldwin on GitHub" rel="nofollow" href="https://github.com/evilpacket">Adam Baldwin on GitHub</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
