TECH

Show HN: DepsGuard – one command to harden NPM/pnpm/yarn/bun/uv configs

Hacker News · Mon, 01 Jun 2026 16:58:52 GMT

I kept seeing every npm/pnpm/yarn/bun/uv supply chain post end with the same advice (set a minimum release age, turn off install scripts), and while I know cooldowns are "controversial", they do work. But even if you convince people that they should set cooldowns, it seems many d

Read original source Discuss with A.S.I.S