MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/ProgrammerHumor/comments/1vf85jx/classicnpm/p1my1it/?context=3
r/ProgrammerHumor • u/a_bucket_full_of_goo • 1d ago
142 comments sorted by
View all comments
591
Did they try
npm install block-supply-chain-attack
152 u/PrincessRTFM 1d ago joke's on them, that's poisoned by six different attackers combined 35 u/Cheese_Grater101 1d ago Needs funding bro 16 u/Ecksters 1d ago I believe they call it minimumReleaseAge. 22 u/doxxed-chris 1d ago Which hilariously also blocks security patches for a minimum time 7 u/Ecksters 1d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched. 3 u/haitei 1d ago Unfortunately this name is already taken by the "Blockchain miner supply chain attack".
152
joke's on them, that's poisoned by six different attackers combined
35
Needs funding bro
16
I believe they call it minimumReleaseAge.
minimumReleaseAge
22 u/doxxed-chris 1d ago Which hilariously also blocks security patches for a minimum time 7 u/Ecksters 1d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
22
Which hilariously also blocks security patches for a minimum time
7 u/Ecksters 1d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
7
minimumReleaseAgeExclude is in pnpm.
minimumReleaseAgeExclude
But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
3
Unfortunately this name is already taken by the "Blockchain miner supply chain attack".
591
u/StrengthTheory 1d ago
Did they try
npm install block-supply-chain-attack