indie-techie
Defensive tools on Linux: Securing the package supply chain
In this article we will answer the following question: āIām a solo developer (or power user) who lives in Python, Node.js, Rust, Go, etc. every day. My language package managers keep installing vulnerable, outdated, or outright malicious packages straight into my environment. How do I actually gatekeep the