|
|
|
Ask HN: How do you defend against supply chain attacks today?
|
|
5 points
by elric
32 days ago
|
|
Seems like software supply chain attacks have been increasing in speed, scope, and complexity of late. Especially in NPM and PyPi packages. How are people defending against this increased threat? Relying on dependency scanners seems way too slow now. Automagically updating to the latest & greatest is likely to include the latest & greatest malware. Auditing every version of every dependency in use is going to be a costly affair. |
|
Edit: this approach sounds like it could be bundled into a couple of agents.