Hacker News new | ask | show | jobs
by clbrmbr 280 days ago
Re: updates: I was just thinking of waiting a few weeks on the updates to allow compromised packages to be discovered.
1 comments

socket.dev will find most malware within hours of it being published.

with LavaMoat most malware won't work even if you don't detect it.