minus-squaretjoa@feddit.orgtoSelfhosted@lemmy.world•Bitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply Chain Incident.linkfedilinkEnglisharrow-up5·20 hours agoBut why does NPM enable post install scripts by default? Why is there no way to define a minimum release age for dependency versions? It’s just poor design choices. linkfedilink
But why does NPM enable post install scripts by default? Why is there no way to define a minimum release age for dependency versions? It’s just poor design choices.