{"podcast":{"title":"DevOps Paradox","slug":"devops-paradox","podcast_index_feed_id":16679,"rss_url":"https://devopsparadox.libsyn.com/rss","website_url":"https://www.devopsparadox.com/","image_url":"https://static.libsyn.com/p/assets/1/3/f/9/13f9df88b6a5bdd1/Devops_Final.jpg","author":"Darin Pope","episode_count":372,"summary":"What is DevOps? We will attempt to answer this and many more questions.","last_synced_at":"2026-09-16T22:22:09.157141+00:00","page_url":"https://stenobird.com/podcast/devops-paradox"},"episode":{"title":"DOP 366: How to Prevent npm Supply Chain Attacks","slug":"dop-366-how-to-prevent-npm-supply-chain-attacks","published_at":"2026-09-02T10:00:00+00:00","page_url":"https://stenobird.com/podcast/devops-paradox/dop-366-how-to-prevent-npm-supply-chain-attacks","show_page_url":"https://stenobird.com/podcast/devops-paradox","url":"https://www.devopsparadox.com/episodes/how-to-prevent-npm-supply-chain-attacks-366/","audio_url":"https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/devopsparadox/dop366-how-to-prevent-npm-supply-chain-attacks.mp3?dest-id=1254752","summary":"#366: You ran npm install this morning. Maybe you ran it a dozen times. Every one of those pulled down a dependency tree you have never read, from a registry that spent years in maintenance mode, and then executed whatever preinstall and postinstall scripts happened to be in there. On your laptop. With your keys sitting on disk. Trusted publishing, provenance, staged releases - all good, all recent, and none of it stops a package from shipping malware. In this episode, we speak with David Mytton, CEO of Arcjet, about defense in depth for the npm ecosystem, and why seven days of patience beats most of your tooling. David's contact information: LinkedIn: https://www.linkedin.com/in/davidmytton/ YouTube channel: https://youtube.com/devopsparadox Review the podcast on Apple Podcasts: https://www.devopsparadox.com/review-podcast/ Slack: https://www.devopsparadox.com/slack/ Connect with us at: https://www.devopsparadox.com/contact/","meta_description":"#366: You ran npm install this morning. Maybe you ran it a dozen times. Every one of those pulled down a dependency tree you have never read, from a regis…","key_points":[],"chapters":[],"topics":[],"duration_seconds":3172,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/devops-paradox/episodes/dop-366-how-to-prevent-npm-supply-chain-attacks/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/devops-paradox/dop-366-how-to-prevent-npm-supply-chain-attacks.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}