logoalt Hacker News

cozzydyesterday at 9:59 PM2 repliesview on HN

That's one way to fix supply chain vulnerabilities.


Replies

tantaloryesterday at 10:10 PM

Can't have any vulnerabilities if you don't have a supply chain

nine_kyesterday at 10:27 PM

More seriously, keeping a local cache of external npm packages, and a local artifact storage for internal npm packages looks like a wise thing to have done long ago. Might be cheaper in the long run.

Ironically, both Nandu and Verdaccio are implemented in Tyepscript and install via npm.

(Same logic obviously applies to Python packages, Docker images, etc.)

show 4 replies