The rise of malicious npm packages—like xlsx-to-json-lh mimicking xlsx-to-json-lc—raises urgent questions. Should npm enforce name uniqueness and vetting to stop supply chain attacks, or risk stifling its open ecosystem? #NpmSecurity #OpenSourceRisks #Cybersecurity
submitted by /u/hongster
[link] [comments]
from Software Development – methodologies, techniques, and tools. Covering Agile, RUP, Waterfall + more! https://ift.tt/mXMQ7xg