<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[dear package registries (npm, composer, etc), i am begging you]]></title><description><![CDATA[<p>dear package registries (npm, composer, etc), i am begging you</p><p>require 2FA before someone can tag a release RIGHT NOW</p><p>this would immediately stop a huge amount of the open source supply chain attacks we keep seeing</p>]]></description><link>https://board.circlewithadot.net/topic/8fdc43f9-a7dd-4ee3-9fd4-e318b51cc9f7/dear-package-registries-npm-composer-etc-i-am-begging-you</link><generator>RSS for Node</generator><lastBuildDate>Sat, 06 Jun 2026 15:55:14 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/8fdc43f9-a7dd-4ee3-9fd4-e318b51cc9f7.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 29 May 2026 01:47:01 GMT</pubDate><ttl>60</ttl></channel></rss>