• Eager Eagle@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    You should probably turn off Dependabot

    Nonsense, most of these supply chain attacks are detected and have their problematic versions pulled within a few hours. Just set a cooldown period for dependabot.