#opensourcerisks — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #opensourcerisks, aggregated by home.social.
-
The rise of malicious npm packages—like `xlsx-to-json-lh` mimicking `xlsx-to-json-lc`—raises urgent questions. Should npm enforce name uniqueness and vetting to stop supply chain attacks, or risk stifling its open ecosystem? #NpmSecurity #OpenSourceRisks #Cybersecurity