Hacker News new | ask | show | jobs
by prisonguard 1160 days ago
> A lot of companies would pay actual money for some semblance of supply-chain security.

After the core-js debacle[0] earlier this year, it was evident that alot of companies actually do not care care about supply-chain security.

Those that do will happily roll their own hosted repositories that provide little to no guarantees.

[0] https://github.com/zloirock/core-js/blob/master/docs/2023-02...