nowfound

Alternatives

Products that do what npm Trusted Publisher does

Secure, secretless npm publishing CLI via GitHub OIDC

  1. 1PF

    The backstory about this GitHub Action: I discussed with an open-source maintainer why they publish npm packages from their local machine and do not use CI/CD pipelines. They said publishing should require human intervention and want to continue using multi-factor authentication to publish to the npm registry. This led to building the wait-for-secrets GitHub Action. It prints a URL in the build log and waits for secrets to be entered using a browser. Once entered, the workflow continues, and secrets can be used in future steps. The latest release of "eslint-plugin-react" to the npm…

    2022 · github.com

  2. 2
    Phase384

    Open source application secrets manager

    2024

  3. 3

    The right infrastructure, auto-provisioned in your cloud

    2022

  4. 4

    Give AI access to 6754+ APIs with zero credentials exposed

    Feb 2026 · keychains.dev

  5. 5
    Keep108

    Alerting, by developers, for developers

    2023

  6. 6

    Skip migration and launch MCP with built-in Auth

    Nov 2025 · arcade.dev

  7. 7TT

    Hi everyone, given the recent increase of attacks on the NPM supply chain, I've put together a list of tips and tricks to help developers stay secure on this specific topic: https://github.com/bodadotsh/npm-security-best-practices I'd love for you to check it out, and contribute your own insights and best practices to make this a comprehensive resource for the community. Cheers!

    Sep 2025 · github.com

  8. 8
    Phase159

    Open-source secrets management for developers

    2023

  9. 9
    NoMac.app136

    The publishing pipeline built for AI agents: build signed iOS releases, push to TestFlight, and submit to the App Store — no Mac, no Xcode.

    Jul 2026 · nomac.app

  10. 10
    Phase107

    Open source application secrets manager

    2025

  11. 11SN

    This past quarter has been awash with sophisticated npm supply chain attacks like [Shai-Hulud](https://www.cisa.gov/news-events/alerts/2025/09/23/widesprea...() and the [Chalk/debug Compromise](https://www.wiz.io/blog/widespread-npm-supply-chain-attack-b...). This CLI helps protect users from recently compromised packages by only downloading packages that have been public for a while (default is 90 days or older). Install: npm install -g @dendronhq/safe-npm Usage: safe-npm install react@^18 lodash How it works: - Queries…

    Nov 2025 · github.com

  12. 12
    Deposure185

    Launch your APIs live effortlessly

    2025

  13. 13
    Shelve156

    Effortless & secure secrets management

    2025

  14. 14OS

    I built this as a small side project to learn and experiment, and I ended up with this! I used a subdomain from my personal portfolio, and everything else runs on free tiers. The project uses Nuxt, SVG, Cloudflare Workers, D1 (SQL), KV, Terraform, and some agentic coding with OpenAI Codex and Claude Code. What started as a joke among friends turned into a fun excuse to build something end to end, from zero to production, and to explore a few things I’d never touched before. I’d really appreciate any feedback or suggestions.

    Jan 2026 · certificate.brendonmatos.com

  15. 15

    Instantly provision production-ready infrastructure

    2023

  16. 16IM
  17. 17
    DexCode94

    Your AI Agent builds the Deck & you never leave the terminal

    Mar 2026 · co-r-e.github.io

  18. 18KC

    Hi Hacker News! Shahar and Tal from Keep Here. We were tired of creating alerts for our applications, so we've built an open-source GitHub Bot that lets you write application alerts using plain English. The code is open-sourced: https://github.com/keephq/keep so you can review it yourself. Every developer and DevOps professional is familiar with the fact that in order to ensure your application works in production, you need to access your observability tool's user interface (such as Grafana, Datadog, New Relic, etc.) and carefully determine how to create alerts that…

    2023 · github.com

  19. 19

    Test data as code: YAML rules, Git versioned, & CI/CD ready

    Dec 2025 · gomask.ai

  20. 20AU

    A lot of vendors and open-source projects shared guidance on protecting users from downloading malicious NPM packages after the Shai-Hulud campaign — but almost nothing focused on protecting maintainers from accidentally (or maliciously) publishing them. So we built a small tool that continuously monitors your NPM packages and automatically unpublishes any version not produced by your CI workflow.

    Nov 2025 · github.com

  21. 21

    I don't know Rust. Friday after work I realised that 90% of my IDE time now is just the commit/diff view — and even good IDEs feel heavy for that. So over the weekend I built a dedicated native tool for just that. Kyde is a macOS git commit + diff editor with one goal: be fast, do Git well. I'm curious whether anyone else mostly opens their IDE for git operations these days. It's open source, and there's a signed app in Releases.

    Jun 2026 · github.com

  22. 22

    One command to a publish-ready TypeScript CLI

    2025

  23. 23NS

    Free and open source, npflared is a serveless private npm registry that you can self-host in order to distribute private packages for you and your team

    2024 · npflared.thomas-cogez.fr

  24. 24AA

    I tend to create a private certificate authority for every side project, in order to create TLS certs for local development. I find it useful to have local development closely resemble production when at all possible, and "real" certificates are an important element. Anyway I got tired of having these CA private keys on my local machine, especially as I started thinking about setting up a private CA for my company (https://riza.io). So I started thinking about what the simplest way to host a private CA might be. You really only need two things: 1) secret storage, to hold the CA's…

    2024 · github.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →