HOW TO AVOID RIGGED NPM PACKAGES. Today, Axios, one of the most popular packages on npm, got compromised. Axios is an HTTP request client. If you installed axios from the npm package repository, you are screwed now. Your organisation is screwed as well. But this can be avoided. Use pnpm, a drop-in replacement for npm. It has the minimumReleaseAge setting to avoid fresh releases. The compromised releases are likely to be noticed within a week. pnpm.io/supply-chain-security

From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments