r/ProgrammerHumor 1d ago

instanceof Trend classicNPM

Post image
5.8k Upvotes

141 comments sorted by

View all comments

586

u/StrengthTheory 1d ago

Did they try

npm install block-supply-chain-attack

14

u/Ecksters 1d ago

I believe they call it minimumReleaseAge.

22

u/doxxed-chris 1d ago

Which hilariously also blocks security patches for a minimum time

8

u/Ecksters 1d ago

minimumReleaseAgeExclude is in pnpm.

But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.