• Victor@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      17 hours ago

      We just recently switched from npm to pnpm, due to all the supply chain attacks. I did the PR for it, even.

      Our release schedule is like a year though so we don’t really have to worry much about releasing compromised dependencies. But still, better to be on the safer side.

    • quick_snail@feddit.nl
      link
      fedilink
      English
      arrow-up
      3
      ·
      22 hours ago

      Yep. And so many workplaces have had security vulnerabilities caused by dumb decisions that could have been easily avoided