After the litellm incident on PyPI, and then axios on npm, I came across this trick on Twitter: configure your package manager to reject dependency releases that are too new.
Note#204
2026-04-01
After the litellm incident on PyPI, and then axios on npm, I came across this trick on Twitter: configure your package manager to reject dependency releases that are too new.
uvnpmbun