logoalt Hacker News

michaelchisari • today at 1:34 PM • 1 reply • view on HN

They're referring to supply chain attacks. Taking over open source libraries through social engineering and adding hidden malicious code. Becoming increasingly common.


Replies

dotancohen • today at 3:27 PM

One could disable updates of dependencies - especially near-real-time updates. Just updating a week after everybody else will have a lot of potential harm with libraries that have a large user base.