logoalt Hacker News

wowohwowlast Saturday at 10:23 PM3 repliesview on HN

You have not been in the field very long than I presume? There's multiple per year that require all hands on deck depending on your tech stack. Just look at the recent NPM supply chain attacks.


Replies

mjr00last Saturday at 10:31 PM

You presume very incorrectly to say the least.

The npm supply chain attacks were only an issue if you don't use lock files. In fact they were a great example of why you shouldn't blindly upgrade to the latest packages when they are available.

show 2 replies
Aeolunyesterday at 12:43 AM

We use pretty much the entire nodejs ecosystem, and only the very latest Next.js vulnerability was an all hands on deck vulnerability. That’s taken over the past 7 years.

procaryoteyesterday at 8:04 AM

You solve a bunch of them by not using javacript in the backend though

show 1 reply