Concepts
What is a CVE, and how do you know if you are affected?
You keep seeing CVE-2024-something in advisories and dependency warnings. Here is what that ID actually is — and the more useful question of whether it touches you.
Tag
You keep seeing CVE-2024-something in advisories and dependency warnings. Here is what that ID actually is — and the more useful question of whether it touches you.
Most supply-chain incidents are a single bad package. Shai-Hulud was different: it used what it stole to publish itself into more packages, on its own.
Most dependency supply-chain risk is blunted by three boring npm settings. They are not glamorous, but they remove the easy ways a bad package slips in.
Your app ships dozens of packages you never chose. When one gets hijacked, you ship the attack too. Here is the pattern, the big recent incidents, and the defenses.