Post #2522225
2026-03-31 08:41 UTC
@xgebi@hachyderm.io dependabot lets you set a minimum age of a dependency before a PR is raised, something like 7+ days old apparently protects against these attacks affecting you -by then it's already surfaced and the malware blocker will be at work.
Key: never be in a rush to update your NPM dependencies. If you must use NPM
#cybersecurity
Replies (0)
No replies.