Settings

Theme

Protecting your Supabase projects from NPM supply chain attacks

supabase.com

3 points by thinkingemote a month ago · 1 comment

Reader

benoau a month ago

Meat of the advice is pin dependency versions and disable install scripts with "npm config set ignore-scripts true", nothing updates accidentally and nothing runs immediately when updates do happen.

Also minimum package ages, but it would be surprising if malicious stuff doesn't stay inert for a day or two by now to mitigate that.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection