The State of the open-source supply-chain
Cheaper software means more dependencies, and more dependencies mean more attack surface. Drawing on Ossprey's research into recent npm and PyPI campaigns, Valentino examines what AI-accelerated development has genuinely changed about open-source supply chain risk and why shortening the window between a malicious package landing and being caught is increasingly crucial.