So I guess I have some learning to do about this recent supply chain attack and npm stuff 👀
No recent project I'm working on has Axios as a dependency, these in the screenshot are old. But it's time I understood a bit more on how to stay safe. Open to any wisdom!
Found this article regarding the incident
https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/
So from the sounds of it, had I been doing an npm install within that two hour window I could have been affected? just like that? That's scary.
