Hacker News
new
past
comments
ask
show
jobs
points
by
sysguest
2 hours ago
|
comments
by
datsci_est_2015
1 hours ago
|
[-]
Leaves you open to vulnerabilities in overnight builds of NPM packages that increasingly happen due to LLM slop?
reply
by
__float
53 minutes ago
|
parent
|
[-]
You can set a minimum age for packages (
https://docs.github.com/en/code-security/reference/supply-ch...
), though that's not perfect (and becomes less effective if everyone uses it).
reply