|
|
|
|
|
by jasonpeacock
1701 days ago
|
|
Let's say that the day you update your dependencies is after this malware was injected but before it was noticed. Now you have malware in your local repo :( Having a local repo does not prevent malware. Your exposure to risk is less because you update your dependencies less frequently, but the risk still exists and needs to be managed. There's no silver bullet. |
|