Latest post
Vibe Coding, Maven, and the Dependencies You Didn’t Choose
Table of Contents So Vibe Coders?Java isn’t npm. Good. Don’t relax.What Price Code AI Gen?Crossing ecosystems can be bad for your (app) healthThe weakest link?Defences for Java DevelopersYour repository configuration is part of the attack surface tooWhat if you can’t ...
-
Namespace Shadowing (a.k.a. “Dependency Confusion”) Attack
The npm Registry is vulnerable to supply chain namespace shadowing, also known as “Dependency Confusion” attacks.
Make sure you create npm scoped packages and force exclude patterns.
1-2 of 2