I really need to get around to publishing my "#Microsoft are bad landlords" post where I rip into them for doing absolutely nothing with #npm to make it more secure (and also owning VSCode, GitHub and all the other tools that make supply-chain attacks easy)

arstechnica.com/security/2024/

Follow

@tanepiper would containerization sandbox this issue?

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.