Safe Chain now enforces a minimum package age before install
aikido.dev | blog | #supply-chain | #devsecops | #malware | #npm | #aikido | #package-registry | #safe-chain
Summary
Safe Chain holds npm versions published in the last 24 hours for analysis before install, falling back to older clean versions—closing the timing window attackers exploit in supply chain campaigns.
- Published
- Collected
Skip to content