home.social

#opensourcerisks — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #opensourcerisks, aggregated by home.social.

fetched live
  1. The rise of malicious npm packages—like `xlsx-to-json-lh` mimicking `xlsx-to-json-lc`—raises urgent questions. Should npm enforce name uniqueness and vetting to stop supply chain attacks, or risk stifling its open ecosystem?

    saysomething.hashnode.dev/npms