Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sumstrem
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
sumstrem
5y ago
The risk with relying on notifications is that it's retroactive and you are already exposed. Instead of attempting to stop threats before they enter your supply chain.
2.
▲
by
sumstrem
5y ago
The idea is that the safety delay would protect your organization from automatically (and in many cases unintentionally) updating to a new compromised dependency version, where you are unaware of a problem. In the case with security fixes a
3.
▲
by
sumstrem
5y ago
Hey HN, In light of this week’s discussion on the corrupted NPM packages colors/fakers ( https://news.ycombinator.com/item?id=29863672 ) the article describes one of our security features that enforces a delay before n
4.
▲
Is open source activism the “new” supply chain threat?
(bytesafe.dev)
5 points
by
sumstrem
5y ago
|
10 comments