logoalt Hacker News

bakugoyesterday at 9:56 PM1 replyview on HN

I highly recommend enforcing a minimum dependency release age of at least a week across all package managers used at your workplace. Most package managers support it now, and it will save you from the vast majority of these attacks.

https://news.ycombinator.com/item?id=47582632


Replies

AgentMEyesterday at 10:13 PM

Highly recommend using the minimum release age setting, though I think a week is probably overkill. Did any of the recent supply-chain attacks have a malicious version up for more than a day?

show 1 reply