1 article with this tag
Adding a dependency means running someone else's code with your privileges, so the defense belongs at install time. This site's view: signatures and provenance were walked straight through in this campaign, so they cannot be the basis of trust. What works is disabling install scripts by default, letting dependencies age a few days before adopting them, and keeping tokens short-lived and narrowly scoped. And if you suspect infection, the order in which you revoke matters.