SaaSHub helps you find the best software and product alternatives Learn more →
Top 10 JavaScript package-manager Projects
-
npm Repository Yarn Repository pnpm Repository
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
-
They have taken action as of very recently. The latest version [1] of npm warns when there are install scripts and tells you they will be disabled by default in a future version, with a per-dependency opt in mechanism [2].
[1] https://github.com/npm/cli/releases/tag/v11.16.0
[2] https://github.com/npm/rfcs/pull/868
-
Project mention: Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT | dev.to | 2026-03-31
Additionally, consider using and rolling to your developers the npq open-source project that introduces security and health signal pre-checks prior to installing dependencies.
-
> they've taken no action.
Not running lifecycle scripts by default is eventually going to be the default behavior. Late is worse than not at all. https://github.com/npm/rfcs/pull/868
-
-
packageSorter
🔄 Dependencies sorting algorithm. It sorts, retrieves unsortable, and returns sorting history for each package
-
-
-
npm-mcp
MCP server for npm package management — 32 tools for publish, install, audit, search, security & more
npm-mcp is an MCP server that gives your AI agent direct access to the entire npm lifecycle. Over 32 tools covering publish, version, audit, access control, deprecation, search, metadata -- basically everything you'd ever do on npmjs.com or in your terminal with the npm CLI.
JavaScript package-manager discussion
JavaScript package-manager related posts
-
NPM packages from RedHat have been compromised
-
NPM introduces allowScripts opt-in install-script policy
-
Maybe you shouldn't install new software for a bit
-
The NPM CLI has 65 production dependencies from the NPM registry
-
What the Axios Supply Chain Attack Revealed About Lockfiles and pnpm 10
-
Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT
-
This specific GitHub issue is crashing
-
A note from our sponsor - SaaSHub
www.saashub.com | 5 Jun 2026
Index
What are some of the best open-source package-manager projects in JavaScript? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | yarn | 41,509 |
| 2 | Bower | 14,929 |
| 3 | cli | 9,805 |
| 4 | npq | 1,676 |
| 5 | rfcs | 768 |
| 6 | nve | 711 |
| 7 | packageSorter | 10 |
| 8 | our-own-npm | 6 |
| 9 | sumo-tab | 5 |
| 10 | npm-mcp | 0 |