dunglas,
@dunglas@mastodon.social avatar

Supply chain attacks are a plague in the ecosystem. is less affected, but we can do even better! I just proposed a patch to to detect when your dependencies introduce new dependencies from sources you don't trust.

We will use this feature to improve the security of @symfony and @ApiPlatform. It should also be possible to port this idea to @npmjs and other package managers 🤝

https://github.com/composer/composer/pull/11460

  • All
  • Subscribed
  • Moderated
  • Favorites
  • javascript
  • ngwrru68w68
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • megavids
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • provamag3
  • JUstTest
  • All magazines