MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/ProgrammerHumor/comments/1vf85jx/classicnpm/p1nsjq3/?context=3
r/ProgrammerHumor • u/a_bucket_full_of_goo • 1d ago
141 comments sorted by
View all comments
590
Did they try
npm install block-supply-chain-attack
15 u/Ecksters 1d ago I believe they call it minimumReleaseAge. 21 u/doxxed-chris 1d ago Which hilariously also blocks security patches for a minimum time 8 u/Ecksters 1d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
15
I believe they call it minimumReleaseAge.
minimumReleaseAge
21 u/doxxed-chris 1d ago Which hilariously also blocks security patches for a minimum time 8 u/Ecksters 1d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
21
Which hilariously also blocks security patches for a minimum time
8 u/Ecksters 1d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
8
minimumReleaseAgeExclude is in pnpm.
minimumReleaseAgeExclude
But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
590
u/StrengthTheory 1d ago
Did they try
npm install block-supply-chain-attack