pull down to refresh
65 sats \ 0 replies \ @WeAreAllSatoshi 9 Sep \ parent \ on: NPM security: preventing supply chain attacks | Snyk (2022) security
It’s certainly still a viable attack vector though, because who checks all of their transitive dependencies every time dependabot opens a PR haha