Comment by habinero

6 months ago

A lot of libraries are maintained by a single person.

Are those the ones typically involved in supply chain attacks?

There are no perfect solutions; but, let's be reasonable.