<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Supply-Chain on westerweel.work</title><link>https://westerweel.work/tags/supply-chain/</link><description>Recent content in Supply-Chain on westerweel.work</description><generator>Hugo</generator><language>nl</language><lastBuildDate>Mon, 18 May 2026 22:25:05 +0200</lastBuildDate><atom:link href="https://westerweel.work/tags/supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>Vijf regels config tegen supply-chain attacks (npm + PyPI)</title><link>https://westerweel.work/posts/2026-05-18-npm-supply-chain-cooldown/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://westerweel.work/posts/2026-05-18-npm-supply-chain-cooldown/</guid><description>npm haalt kwaadaardige versies binnen 24-48 uur offline; PyPI zet ze binnen uren in quarantaine. Een wachttijd van zeven dagen — vijf regels config — laat dat venster voor je werken.</description></item></channel></rss>