Node.js · Security · Mid-Level · Best Practice
Dependency supply-chain hardening for Node?
Short Interview Answer
Lockfiles, npm audit/OSV in CI, pinned versions, ignore scripts when possible, and review install hooks.
Detailed Explanation
Use private registries for critical orgs. Monitor for typosquatting. Reproducible builds matter.