https://github.com/wesleytodd
socket.dev/blog/shai-hu...
socket.dev/blog/shai-hu...
socket.dev/blog/shai-hu...
What was that again about trusted publishing? You need to trust your CI for it's threat model to apply? Guess maybe that's a bad place to put our trust.
What was that again about trusted publishing? You need to trust your CI for it's threat model to apply? Guess maybe that's a bad place to put our trust.
Hate on Austin all you want (especially since it’s in Texas) but I still love this place.
Hate on Austin all you want (especially since it’s in Texas) but I still love this place.
#javascript #nodejs #packages
#javascript #nodejs #packages
You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
Here is that guidance 👇
We've released updated guidance to help maintainers reduce exposure, strengthen release processes, and protect the ecosystem: openjsf.org/blog/publish...
Here is that guidance 👇
github.com/expressjs/di...
github.com/expressjs/di...
Sorry for your loss Eva.
That’s me!!
Sorry for your loss Eva.
📌 Highlights: stronger threat modelling, npm Trusted Publishing risks tackled, new runtime features for secure‑by‑default apps.
hubs.la/Q03T5j8j0
📌 Highlights: stronger threat modelling, npm Trusted Publishing risks tackled, new runtime features for secure‑by‑default apps.
hubs.la/Q03T5j8j0
(cont'd)
Enjoy 🌞
Enjoy 🌞
(From: protocol.ecologies.info/interviews/n... )
(From: protocol.ecologies.info/interviews/n... )
Couldn't help but think of @https://hachyderm.io/@Di4na's blog post https://www.softwaremaxims.com/blog/not-a-supplier and how it's literally in the […]
@rafaelgss.dev shares all the details about the Node.js release schedule in our new series, JavaScript Security Snapshot.
@rafaelgss.dev shares all the details about the Node.js release schedule in our new series, JavaScript Security Snapshot.