| ▲ | eranation 3 hours ago | |||||||
Exactly this. For anyone who wants to do it for various package managers:
This would have protected the 334 people who downloaded @bitwarden/cli 2026.4.0 ~19h ago (according to https://www.npmjs.com/package/@bitwarden/cli?activeTab=versi...). Same for axios last month (removed in ~3h). Doesn't help with event-stream-style long-dormant attacks but those are rarer.(plug: released a small CLI to auto-configure these — https://depsguard.com — I tried to find something that will help non developers quickly apply recommended settings, and couldn't find one) | ||||||||
| ▲ | m4r71n 3 hours ago | parent [-] | |||||||
| ||||||||