|
|
|
|
|
by snthd
1682 days ago
|
|
>How do we even mitigate against these types of supply-chain attacks, aside from disabling run-scripts, using lockfiles and carefully auditing the entire dependency tree on every module update? Don't trust the package distribution system - use public key crypto. |
|