Hacker News new | ask | show | jobs
by tompazourek 1690 days ago
npm audit reports known vulnerabilities, but I think it doesn't help against supply chain attacks, or does it?