8 ms·
well you know 100% know what dependabot does
by sysguest 6mo ago
well you know 100% know what dependabot does
- datsci_est_2015 6mo agoLeaves you open to vulnerabilities in overnight builds of NPM packages that increasingly happen due to LLM slop?
- __float 6mo agoYou can set a minimum age for packages (https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#cooldown- https://docs.github.com/en/code-security/reference/supply-ch...), though that's not perfect (and becomes less effective if everyone uses it).
- catlifeonmars 6mo ago> becomes less effective if everyone uses it I don’t think that’s necessarily the case. Exposure and discovery aren’t that tightly correlated. Maybe there’s a small effect, but I think it is outweighed by the fact that blast radius and spread is reduced while buying time for discovery.