Software Supply Chain Risk Is a People Problem Now
In 2025 Sonatype counted 454,600 new malicious packages, and the easiest way in was phishing a trusted maintainer. Software supply chain risk is now a people problem, and the fix is verification cheap enough to actually use.
