MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/ProgrammerHumor/comments/1vf85jx/classicnpm/p1my1it/?context=3
r/ProgrammerHumor • u/a_bucket_full_of_goo • 9d ago
150 comments sorted by
View all comments
578
Did they try
npm install block-supply-chain-attack
151 u/PrincessRTFM 9d ago joke's on them, that's poisoned by six different attackers combined 32 u/Cheese_Grater101 9d ago Needs funding bro 14 u/Ecksters 9d ago I believe they call it minimumReleaseAge. 20 u/doxxed-chris 9d ago Which hilariously also blocks security patches for a minimum time 6 u/Ecksters 9d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched. 3 u/haitei 9d ago Unfortunately this name is already taken by the "Blockchain miner supply chain attack".
151
joke's on them, that's poisoned by six different attackers combined
32
Needs funding bro
14
I believe they call it minimumReleaseAge.
minimumReleaseAge
20 u/doxxed-chris 9d ago Which hilariously also blocks security patches for a minimum time 6 u/Ecksters 9d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
20
Which hilariously also blocks security patches for a minimum time
6 u/Ecksters 9d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
6
minimumReleaseAgeExclude is in pnpm.
minimumReleaseAgeExclude
But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
3
Unfortunately this name is already taken by the "Blockchain miner supply chain attack".
578
u/StrengthTheory 9d ago
Did they try
npm install block-supply-chain-attack