Damus
BrianKrebs · 18w
We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloaded some backdoored update.
Alesandro Ortiz ๐Ÿ‡ต๐Ÿ‡ท๐Ÿณ๏ธโ€๐ŸŒˆ profile picture
@nprofile1q... We may need a "safetime" tracker that lets us know when there were no known widely-used packages that were compromised in a repository.

Retroactive, of course, but might be interesting like uptime. e.g. npm might have 98.5% safetime this week based on known compromises.