Not trying to start a fire here, but I’m surprised how quickly the 2025 supply chain attack faded from day-to-day conversations.
Compromised npm packages, malicious code slipping in through trusted GitHub repos, and most teams I talk to still update dependencies like nothing happened. Same workflows, same assumptions.
Was this actually a turning point for anyone, or did we collectively decide it was “someone else’s problem”?