Content pfp
Content
@
0 reply
0 recast
0 reaction

David Furlong pfp
David Furlong
@df
What are the best tools for hardening OSS against supply chain attacks?
7 replies
2 recasts
16 reactions

mike rainbow (rainbow mike) pfp
mike rainbow (rainbow mike)
@mikedemarais.eth
thread https://x.com/brunobar79/status/1389724665338269701?s=46
0 reply
0 recast
2 reactions

Leo will be at Far(away) Con pfp
Leo will be at Far(away) Con
@lsn
@sam’s listen.dev?
1 reply
0 recast
2 reactions

Vinay Vasanji pfp
Vinay Vasanji
@vinayvasanji.eth
@feross's socket.dev
0 reply
0 recast
2 reactions

raz pfp
raz
@raz
I think the only real defense technically is to slow down updates, create test environments, and avoid pushing anything to the main branch within a two-week or longer time window.
0 reply
0 recast
1 reaction

Sam is at FarCon ✦  pfp
Sam is at FarCon ✦
@samantha
Happy to chat 👋
0 reply
0 recast
1 reaction

JB Rubinovitz  pfp
JB Rubinovitz
@rubinovitz
Snyk is the only tool I've heard about https://snyk.io/series/software-supply-chain-security/attacks/
0 reply
0 recast
1 reaction

Samuel is @Farcon you too? DM! pfp
Samuel is @Farcon you too? DM!
@samuellhuber
https://www.npmjs.com/package/audit-ci is nice, sharing more as I search
1 reply
0 recast
0 reaction