Why CI-Based Security is Too Late for Modern Node.js Projects (opens in new tab)
Most Node.js teams rely on CI pipelines to tell them whether their dependencies are secure. By the time that feedback arrives, however, the most important decisions have already been made.
Read the original article