Earlier today, npm, Inc. announced its acquisitionof the team and assets of ^Lift Security, including their work on the Node Security Platform. Adam Baldwin and his team have joined npm to work full time on keeping the npm Registry and npm applications safe, and to create new products to help developers and their companies securely develop JavaScript.
^Lift Security has been working with npm longer than npm, Inc. has been a company. They review npm's own code to ensure it's safe before we take it live, and conduct periodic security audits, including penetration tests of our services. Most prominently, the Node Security Platform has become a definitive catalogue of JavaScript vulnerabilities for developers and security vendors.
npm is where the Node Security Platform belongs. All NSP users are npm users, and the security of open source code is core to npm's mission. By combining our resources, we can deliver a continuous approach to security at scale, empowering millions of developers to build more secure code.
As one team, we'll continue keeping the registry safe, and develop new ways to help individuals and companies understand and trust the JavaScript code that they write and share.