@coderbyheart on Twitter

A static archive of Markus Tacker's tweets. Follow me on Mastodon: @[email protected].

Home / Archive / 2019 / 2019-12 / 1210341353521139714

Another way to mitigate this attack is to only let trusted sources update the
package-lock.json (👋 @greenkeeperio).
https://snyk.io/blog/why-npm-lockfiles-can-be-a-security-blindspot-for-injecting-malicious-modules/

Thu, 26 Dec 2019 23:27:20 UTC♥ 5↻ 1