Supply-chain attacks on open source software are getting out of hand arstechnica.com 5 points by akyuu 19 hours ago