The npm registry’s safe word is Socket
GitHub’s JavaScript failings are someone else’s opportunity
Exclusive Socket has found a way to protect developers from npm, GitHub’s insufficiently safe JavaScript package manager, by wrapping it in a security blanket.…
Author: Thomas Claburn. [Source Link (*), The Register]