A VS Code extension buffers NPM updates to avoid supply chain attacks
A VS Code extension buffers NPM updates to avoid supply chain attacks
I had been using package.json version keepers for quite some time but after the big supply chain attack i thought they would be the perfect place to add in some security. The idea is just to provide the latest package number x days old. This will help prevent most of the danger in supply in chain attacks. It will also remove the `^` if you have it so you can better control what version of a package your application is using. To be more security focused it gives general hints in the hover menu to help keep an eye on the packages you have installed. These hints include warnings for staleness, high dependency count, and number of downloads. Since all of this is something you can get through the npm api, I called it tinyNpm
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
New NPM Supply chain Attack?
Typewriter, my first VS Code extension
What's That Slang – VS Code extension for expansion of slangs
Markwhen VS Code Extension
Mitigate against 0-day supply chain attacks with safe-NPM
PasteOverflow – VS Code extension for instant code pasting from SO
Related Files extension for VS Code
VS Code GoLang Productivity Extension
Tooltitude for Go – productivity extension for Golang for VS Code
Webhooks development relay with VS Code extension