Hardening · updates · supply chain

Update safely (avoid fake downloads)

When projects go viral, fake installers and malicious extensions show up. Treat updates as a security action, not a casual click.

Rules

  • Download only from official sources and verify links.
  • Prefer package manager installs over random binaries from posts.
  • Keep rollback paths (snapshots/backups) before updating.

Related

Fake extensions / malware

What scams look like in practice.

Read →

Secrets hygiene

Updates often involve tokens and configs — don’t leak them.

Read →

Exposure check

After updating, re-check exposure and binds.

Read →