You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If an npm package is compromised at 09:00, who is exposed by 09:06? Version-aware supply-chain impact on HydraDB — dependency tree, publish-rights reach, temporal lockfile windows, OSV-matched. Hack Hydra 2026 Track 2A.
Supply-chain blast radius for npm, built on HydraDB. Answers what is exposed when a package is compromised — including the packages reachable through shared publish rights that dependency scanning misses. Hack Hydra 2026, Track 2A.