AWS Security Blog 中文 关注 在 Amazon Linux 中安全更新 npm 和 pip 软件包 “如果您使用并安装来自 npm 或 PyPI 的包,在包发布后的最初几小时风险最高,因为扫描器无法在发布前分析这些包。近期影响 Node.js 和 Python 包的供应链事件已在数小时内被检测并移除。然而,尽管这些包曾对公众开放,但……" Secure your npm and pip package updates in Amazon Linux aws.amazon.com AWS Security Blog 中文 RSS thenote.app