Hacker News new | ask | show | jobs
by goodpoint 521 days ago
> Doing a open source supply chain attack is not easy

When projects ship 600 dependencies it's really easy.

> not easy, fast or reliable for long.

It does not need to be long. One day is enough to compromise a system or a thousand.