Skip to main content


“The mysterious supply chain concern of string-width-cjs npm package | Snyk”

https://snyk.io/blog/supply-chain-string-width-cjs-npm/

> It is my assumption that all of these dependent packages and download boosts are leading to the sole purpose of creating false legitimacy for the 3 *-cjs package

Fun fun fun.

reshared this

in reply to Baldur Bjarnason

@Baldur Bjarnason That is why we need signatures (not just simple/weak MD5) on packages, to check if it is the same. Only during setup/adding or upgrade phase you need to watch out, if the right signature was added.