Supply-chain attacks on open source software are getting out of hand arstechnica.com 5 points by akyuu 2 days ago