
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
npm-completion
Advanced tools
npm and yarn completion including package names for bash and zsh
this script will list/complete package names for remove, update and install commands.
when there are multiple options it will list them.
when theres only one possible option it will complete it.
![npm install npm-comp[tab] #output #npm-compact npm-compat npm-completion npm-comp-stat-www npm install npm-compl[tab] #result #npm install npm-completion](https://github.com/Jephuff/npm-completion/raw/HEAD/example.gif)
install will look at all package names on npm. Remove and update will look at locally installed packages(if -g is in the command, it will look at global packages).
package list updated at 3am ET everyday so it's recommended that you run the update command periodically.
npm-completion-update
$ git clone https://github.com/Jephuff/npm-completion
$ ./npm-completion/setup
$ ./npm-completion/update
$ npm i -g npm-completion
if you use sudo to install, you will need to run the setup script manually
$ npm-completion-setup
$ npm-completion-update
you will need to download the windows version
$ npm i -g npm-completion@windows
$ npm-completion-setup
set INCLUDE_YARN_COMPLETION to false in your .bashrc above the npm-completion lines to exclude yarn completion
INCLUDE_YARN_COMPLETION=false
# added for npm-completion https://github.com/Jephuff/npm-bash-completion
FAQs
bash and zsh completion script for npm package names.
The npm package npm-completion receives a total of 0 weekly downloads. As such, npm-completion popularity was classified as not popular.
We found that npm-completion demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.