dear package registries (npm, composer, etc), i am begging you
Uncategorized
1
Posts
1
Posters
8
Views
-
dear package registries (npm, composer, etc), i am begging you
require 2FA before someone can tag a release RIGHT NOW
this would immediately stop a huge amount of the open source supply chain attacks we keep seeing
-
D dansup@mastodon.social shared this topic
R relay@relay.mycrowd.ca shared this topicR relay@relay.an.exchange shared this topic