pull down to refresh
166 sats \ 1 reply \ @k00b 23h \ parent \ on: NPM security: preventing supply chain attacks | Snyk (2022) security
Yep, my understanding too
It’s certainly still a viable attack vector though, because who checks all of their transitive dependencies every time dependabot opens a PR haha
reply