codeinabox@programming.dev to Programming@programming.devEnglish · 2 months agoEvery dependency you add is a supply chain attack waiting to happenbenhoyt.comexternal-linkmessage-square30linkfedilinkarrow-up1171arrow-down11cross-posted to: technology@lemmy.worldlobsters@lemmy.bestiver.se
arrow-up1170arrow-down1external-linkEvery dependency you add is a supply chain attack waiting to happenbenhoyt.comcodeinabox@programming.dev to Programming@programming.devEnglish · 2 months agomessage-square30linkfedilinkcross-posted to: technology@lemmy.worldlobsters@lemmy.bestiver.se
minus-squareEager Eagle@lemmy.worldlinkfedilinkEnglisharrow-up53·2 months ago You should probably turn off Dependabot Nonsense, most of these supply chain attacks are detected and have their problematic versions pulled within a few hours. Just set a cooldown period for dependabot.
Nonsense, most of these supply chain attacks are detected and have their problematic versions pulled within a few hours. Just set a cooldown period for dependabot.
The discovered ones anyway.