Alternatives
Products that do what ZPDer – informs you when an NPM package you use is upgraded does
- 1SW
2016 · npmdiscover.com
- 2

- 3TS
2018 · github.com
- 4PD
2019 · diff.intrinsic.com
- 5BU
Hey HN, we are building bumpgen (https://github.com/xeol-io/bumpgen/) to remove the toil of fixing breaking changes during version bumps. bumpgen bumps your npm package version then generates the fixes to potential breaking changes. There were some interesting challenges we encountered using an LLM to fix breaking changes: [1] Finding the breaking changes → know how is a dependency used through the codebase [2] Knowing how to fix the a breaking change → know how the dependency has changed from one version to another [3] Understanding how the fix has modified existing…
2024 · github.com
- 6

- 7

- 8

- 9NN
2016 · 720kb.github.io
- 10AI
2016 · npmjs.com
- 11BM
2013 · bundlescout.com
- 12AP
2023 · openpm.ai
- 13

- 14IB
Hi HN, I built a tool [1] that resolves breaking changes when you upgrade npm packages. I know keeping my dependencies updated is good hygiene but I really have no motivations to do them. The time to fix breaking changes then validate them makes the ROI lopsided. Automating these helps me reduce the barrier to a good habit. It works on typescript and tsx projects. BYOK (bring your own GPT-4 key) for the codegen. MIT license. How does it work? - Bumps the package version, builds your project, and then runs tsc over your project to understand what breaks - Uses ts-morph [2] to create an AST of…
2024 · github.com
- 15DO
I kept seeing every npm/pnpm/yarn/bun/uv supply chain post end with the same advice (set a minimum release age, turn off install scripts), and while I know cooldowns are "controversial", they do work. But even if you convince people that they should set cooldowns, it seems many don't end up following through, not sure why, maybe because it means hand-editing five config files in five formats with five different time units, or perhaps the "it won't happen to me" syndrome (or "I'll do it later, it seems complicated" where it's actually very simple). So I created a tool that…
Jun 2026 · github.com
- 16JB
2015 · jsbundler.com
- 17SG
2014 · sibbell.com
- 18WM
2017 · ping.pm2.io
- 19NF
2014 · vuln.pub
- 20AU
A lot of vendors and open-source projects shared guidance on protecting users from downloading malicious NPM packages after the Shai-Hulud campaign — but almost nothing focused on protecting maintainers from accidentally (or maliciously) publishing them. So we built a small tool that continuously monitors your NPM packages and automatically unpublishes any version not produced by your CI workflow.
Nov 2025 · github.com
- 21
React Native & Expo Dependency Insights
May 2026 · package-intelligence.vercel.app
- 22PD
2021 · pickbetterpack.com
- 23

Find deprecated npm packages before they haunt your prod app
May 2026 · stackgraveyard.dev
- 24UA
2025 · github.com
Ranked by how close each launch is in meaning, then by votes. Refine with a description →