Skip to content
npm audit isn't enough: I simulated a supply chain attack on my Node dependencies and found what the scanner can't see — txtfeed | txtfeed