Content pfp
Content
@
0 reply
0 recast
0 reaction

David Furlong pfp
David Furlong
@df
What are the best tools for hardening OSS against supply chain attacks?
7 replies
1 recast
12 reactions

Leo pfp
Leo
@lsn
@sam’s listen.dev?
1 reply
0 recast
1 reaction

mike rainbow (rainbow mike) ↑ pfp
mike rainbow (rainbow mike) ↑
@mikedemarais.eth
thread https://x.com/brunobar79/status/1389724665338269701?s=46
0 reply
0 recast
1 reaction

Samuel pfp
Samuel
@samuellhuber.eth
https://www.npmjs.com/package/audit-ci is nice, sharing more as I search
1 reply
0 recast
0 reaction

JB Rubinovitz ⌐◨-◨ pfp
JB Rubinovitz ⌐◨-◨
@rubinovitz
Snyk is the only tool I've heard about https://snyk.io/series/software-supply-chain-security/attacks/
0 reply
0 recast
0 reaction

Vinay Vasanji pfp
Vinay Vasanji
@vinayvasanji.eth
@feross's socket.dev
0 reply
0 recast
2 reactions

Sam (crazy candle person) ✦  pfp
Sam (crazy candle person) ✦
@samantha
Happy to chat 👋
0 reply
0 recast
1 reaction

raz pfp
raz
@raz
I think the only real defense technically is to slow down updates, create test environments, and avoid pushing anything to the main branch within a two-week or longer time window.
0 reply
0 recast
1 reaction