Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
NPM安全审计:你的团队仍然需要的缺失层
aikido.dev
| 博客 |
#supply-chain
|
#npm
|
#audit
|
#nodejs
|
#dependencies
摘要
使用 Node.js 越久越会发现:最大的安全风险来自你没写过的包和没见过的维护者。文章指出内置 npm audit 的不足,说明团队仍需在依赖生命周期上补齐一层完整的安全审计。
发布时间
2025-08-13 00:00
收录时间
2026-07-04 09:44
原文 ↗
相关内容
Shai-Hulud 沉寂 111 天后死灰复燃
(aikido.dev)
为什么 npm 会拉取不在我 package-lock.json 中的依赖?
(hackerone.com)
PhantomRaven:为漏洞赏金猎捕而开发的 LLM 生成信息窃取器
(crowdstrike.com)
软件包安全实战:非官方指南
(wiz.io)
From DEF CON Research to Automated Supply Chain Defense, finding npx confusion vulnerabilities with npxconfuse
(lab.ctbb.show)
lottie-player 供应链攻击:你需要知道的一切
(wiz.io)
返回