Post by Gajus on X
Gajus@kuizinas
XThere is a surge of supply chain attacks (and it is only going to get worse)
If you are using pnpm, take these steps to protect yourself:
* set minimumReleaseAge to 7 days
* set blockExoticSubdeps to true
* configure onlyBuiltDependencies
npm / yarn have similar settings
708 likes13 repliesPosted Apr 30, 2026