GitHub announces npm security changes to tackle supply-chain attacks
(bleepingcomputer.com)
1.
2.
Two new RSC protocol vulnerabilities uncovered
(news.ycombinator.com)
3.
Show HN: Safe-NPM – only install packages that are +90 days old
(news.ycombinator.com)