Hacker News new | ask | show | jobs
by JulienBrouchier 85 days ago
There are positive things happening too. Recently, npm released min-release-age filtering the lets you only import packages that have a certain vintage, protecting you from all these supply chain attacks as they tend to be quickly detected.

https://github.com/npm/cli/releases/tag/v11.10.0