Content
@
0 reply
0 recast
2 reactions
Dan Finlay 🦊
@danfinlay
There's no excuse to leave critical JS infrastructure this vulnerable to supply chain attacks, thanks to LavaMoat from @metamask. Hasn't been for a few years, but if it takes a big hack to get you to think longer term, then I recommend you seize the opportunity: https://github.com/LavaMoat/LavaMoat
1 reply
14 recasts
99 reactions
sara2003
@sara2003
Can LavaMoat fully prevent supply chain attacks, or does it mainly reduce vulnerabilities? @danfinlay
1 reply
0 recast
0 reaction
Dan Finlay 🦊
@danfinlay
It reduces the risk posed by supply chain attacks to a significantly more tractable and often/likely endurable level. There's no free lunch, but you can limit the risk down to what you are trusting the external code to do (no more), provided the sandbox holds (a constantly improving target).
1 reply
0 recast
0 reaction