JS Party: JavaScript, CSS, Web Development

What's in your package.json?

01.29.2022 - By Changelog MediaPlay

Download our free app to listen on your phone

Download on the App StoreGet it on Google Play

Tobie Langel, Open source strategist and Principal at UnlockOpen, joins Chris, Feross, and Amal to discuss recent widespread incidents affecting the JavaScript community (and breaking CI builds) around the globe. Two widely used npm libraries were self-sabotaged by their single maintainer, yet again, highlighting the many gaps in our OSS supply chain security, sustainability and overall practices. We explore all these topics and solution on what our ecosystem needs to be more resilient to these types of attacks in the future.

More episodes from JS Party: JavaScript, CSS, Web Development