Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Amazon probably builds everything in house. Smaller shops rely more on open source tools like npm or Ruby gems.

I think there are supply chain attack vectors in those resources



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: