Megalodon chums the waters in 5.5K+ GitHub repo poisonings

(theregister.com)

5 points | by sbulaev 13 hours ago ago

2 comments

  • danielcasper 13 hours ago

    Okay, so what's the obvious solution to all this supply chain poisoning?

    • turtleyacht 12 hours ago

      Pin deps. Integrity hashing. Wait to update to latest. Mirror through a proxy. Adhere to code scanner guidelines (--ignore-scripts).