top | item 46976524

(no title)

smithza | 18 days ago

key word "encourages"

when someone uses `npm install/add/whatever-verb` does it default to only using trusted publishing sources? and the dependency graph?

either 100% enforcement or it won't stick and these attack vulnerabilities are still there.

discuss

order

No comments yet.