April 2, 2026 April 2, 2026 Package maturity gates: a simple defense against npm supply chain attacks Many npm supply chain attacks are detected quickly. Delaying very fresh package versions can block a surprising amount of risk for a small cost. securitynodejs