JavaScript Jabber cover image

Guarding the JavaScript Supply Chain: Preventing NPM Attacks with Feross Aboukhadijeh - JSJ 695

JavaScript Jabber

00:00

How GitHub Actions Misuse Enabled Package Compromise

Feross walks through NX's workflow vulnerabilities, shell injections, and pull_request_target token abuse used to steal publish tokens.

Play episode from 11:55
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app