Trust nothing, ship safely: surviving the supply chain attack era

Supply chain attacks are no longer theoretical — they’re a daily reality. npm packages, including some of the most widely used libraries in the ecosystem, have been weaponized to compromise thousands of developers at once. This talk is about getting ahead of it. Nina Torgunakova will demo Multiocular — the open-source tool built at Evil Martians for reviewing dependency changes — on two real updates: one harmless, one malicious. You’ll see what actually separates them once you stop trusting the version number and start looking at the diff. By the end, you’ll know how to ask the one question that matters about everything you depend on: why do I trust this?



