4 ms·Or use some other technology.by romanovcode 9y agoOr use some other technology.eropple 9y agoThere are remarkably few dependency management systems not vulnerable to some variant of this attack.DCoder 9y agoThen again, a project with <20 dependencies has fewer "entry points" for this attack than a typical NPM project with 500+ transitive dependencies.