Conversation

open source supply chain for dummies:

  • being able to delete a raccidentally published package: massive threat to the open source supply chain
  • potentially ongoing malware hijacking raccampaign: [crickets]
1
2
6

if you release a package that depends on all packages including itself that is a hacking attempt and also a threat to supply chain security. obviously.

0
0
1