npm was a mistake. the concept of pulling live dependencies that are not collectively managed by a QA team but each individually managed by many thousands of people with wildly varying skill and availability is inherently doomed to constant incidents.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/0xabad1dea/statuses/115218153651076279 on your instance and quote it. (Note that quoting is not supported in Mastodon.)