open source software or stuff like npm modules ?
You can't, but npm is taking it seriously and runs audits these days. I only import from reputed sources. And when source is freely available to all from the original source, there's less motivation and more resistance to get away with something. I generally only import from well reputed sources or I read source and see why I really need a module before importing.
https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5 I'm harvesting credit card numbers and passwords ... - Hacker Noon
Обсуждают сегодня