pnpm 10.16—interesting idea: “To reduce the risk of installing a compromised version, we are introducing a new setting that delays the installation of newly released dependencies. In most cases, such attacks are discovered quickly and the malicious versions are removed from the registry within an hour.”
https://github.com/pnpm/pnpm/releases/tag/v10.16.0
If you have a fediverse account, you can quote this note from your own instance. Search https://fosstodon.org/users/rauschma/statuses/115197331125182763 on your instance and quote it. (Note that quoting is not supported in Mastodon.)