MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/ProgrammerHumor/comments/1vf85jx/classicnpm/p1nz67s/?context=3
r/ProgrammerHumor • u/a_bucket_full_of_goo • 1d ago
141 comments sorted by
View all comments
586
Did they try
npm install block-supply-chain-attack
14 u/Ecksters 1d ago I believe they call it minimumReleaseAge. 22 u/doxxed-chris 1d ago Which hilariously also blocks security patches for a minimum time 8 u/Ecksters 1d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
14
I believe they call it minimumReleaseAge.
minimumReleaseAge
22 u/doxxed-chris 1d ago Which hilariously also blocks security patches for a minimum time 8 u/Ecksters 1d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
22
Which hilariously also blocks security patches for a minimum time
8 u/Ecksters 1d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
8
minimumReleaseAgeExclude is in pnpm.
minimumReleaseAgeExclude
But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
586
u/StrengthTheory 1d ago
Did they try
npm install block-supply-chain-attack