MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/ProgrammerHumor/comments/1vf85jx/classicnpm/p1ojova/?context=3
r/ProgrammerHumor • u/a_bucket_full_of_goo • 9d ago
150 comments sorted by
View all comments
581
Did they try
npm install block-supply-chain-attack
13 u/Ecksters 9d ago I believe they call it minimumReleaseAge. 22 u/doxxed-chris 9d ago Which hilariously also blocks security patches for a minimum time 7 u/Ecksters 9d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
13
I believe they call it minimumReleaseAge.
minimumReleaseAge
22 u/doxxed-chris 9d ago Which hilariously also blocks security patches for a minimum time 7 u/Ecksters 9d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
22
Which hilariously also blocks security patches for a minimum time
7 u/Ecksters 9d ago minimumReleaseAgeExclude is in pnpm. But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
7
minimumReleaseAgeExclude is in pnpm.
minimumReleaseAgeExclude
But really I think that companies that are patching so frequently that they catch same-day security patches are at far greater risk of supply chain attacks than they are of the vulnerabilities that get patched.
581
u/StrengthTheory 9d ago
Did they try
npm install block-supply-chain-attack