Posted by ezraax on Sep 23 Hi, Sharing a registry-metadata observation that matters for supply-chain incident response. I audited npm's public package documents and found a retention asymmetry. Each package document has a `time` map (per-version publish stamps) and a `versions` map (the manifests).

Read the full article at oss-security →