
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@jesscss/plugin-node-modules
Advanced tools
Import resolver that loads npm packages from node_modules — a seed of the
JavaScript-execution / CSS-in-JS story.
This plugin gives Jess's language plugins a way to resolve and load npm packages
by name, using Node's module resolution (require.resolve /
createRequire). Other plugins use it to pull in packages referenced from a
stylesheet — for example @jesscss/plugin-less-compat
resolving a Less @plugin "package-name" off node_modules.
One of the four tools Jess aims to converge is
CSS-in-JS: running real JavaScript inside your stylesheets (@use /
@plugin) so styles can be dynamic without leaving CSS files. Reaching npm
packages is a building block of that story. Paired with
@jesscss/plugin-js (which executes the modules), it lets a
stylesheet pull logic and data from the JS ecosystem.
That convergence is roadmap — being proven through the alpha, not claimed as done. What ships here today is just the resolver seam; don't read it as a finished CSS-in-JS system.
Alpha. Part of Jess. The programmatic plugin/compiler API is not yet
stabilized — the jess CLI is the documented public surface for the alpha.
Watch the
docs site for the API once it settles.
FAQs
Jess plugin for resolving and loading npm packages from node_modules
The npm package @jesscss/plugin-node-modules receives a total of 83 weekly downloads. As such, @jesscss/plugin-node-modules popularity was classified as not popular.
We found that @jesscss/plugin-node-modules demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.