58
We should all be using dependency cooldowns
(blog.yossarian.net)
Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!
Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.
Hope you enjoy the instance!
Rules
Follow the wormhole through a path of communities !webdev@programming.dev
Most of the supply chain vulnerabilities I've seen published and talked about lately have been trying to do things like exfiltrate keys/secrets from developers, including ci.
So of you've got a pr open with the vulnerable package update on it then you've goofed. Even potentially without merging if you've not got ci set up very securely, which is probably more common than we'd like to admit