Web Development
Your npm Install Just Ran Someone Else's Code: Why Dependency Security Has to Start Before CI
A pull request checkout, a poisoned GitHub Actions cache, and an OIDC token pulled straight out of runner memory. That's how 84 malicious versions of TanStack's packages hit npm in six minutes.