logoalt Hacker News

SkyPunchertoday at 1:39 PM0 repliesview on HN

But, pinning has prevented most of the recent supply chain attacks.

As long as you don't update your pins during an active supply chain attack, the risk surface is rather low.