Good timing on this, since AI-written code pulls in dependencies faster than anyone reviews them. One layer I would add on top of lockfiles and install-script blocking: check build provenance, so you know a package was built from the repo and commit it claims, not uploaded from someone's laptop. Pairing that with a short delay before adopting brand-new versions catches most hijacked releases before they reach you. Have you found a clean way to enforce provenance checks in CI with pnpm yet?
iin1005h0828
Good timing on this, since AI-written code pulls in dependencies faster than anyone reviews them. One layer I would add on top of lockfiles and install-script blocking: check build provenance, so you know a package was built from the repo and commit it claims, not uploaded from someone's laptop. Pairing that with a short delay before adopting brand-new versions catches most hijacked releases before they reach you. Have you found a clean way to enforce provenance checks in CI with pnpm yet?
iin1005h0828