3 ms·
That’s a bold claim to make about HNers. Au contraire, security companies have absolutely missed supply chain attacks. Example: https://snyk.io/blog/node-gyp-
by yearolinuxdsktp 3mo ago
That’s a bold claim to make about HNers. Au contraire, security companies have absolutely missed supply chain attacks.
Example:
https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/ https://snyk.io/blog/node-gyp-supply-chain-compromise-self-p...
Before that we had event-stream, then we had XZ compromise.
It’s not exceptionally hard to delay reaching out to external sites until after a cooldown period.