Search
Feeds
Discover
Login
Debug
Fork on GitHub
See full post
pnpm
pnpm.io
The Seattle Times is piloting pnpm’s client-side defenses—blocked lifecycle scripts, release cooldowns, and trust policy—to stop worms like Shai-Hulud 2.0 before they land. Read their story:
pnpm.io/blog/2025/12...
How We're Protecting Our Newsroom from npm Supply Chain Attacks | pnpm
We got lucky with Shai-Hulud 2.0.
pnpm.io
Dec 8, 2025 13:47
0
reposts
0
quotes
0
likes
Repost
Quote post
View on Bluesky
Copy Bluesky URL
Copy post URL
Translate post
Show all post labels
An unhandled error has occurred.
Reload
🗙