*Pin dependencies
*Have an SCA tool enforce a cool-down period on new packages
*If you use an AI coding tool, tell it to scan your manifest every time it's updated via an MCP server
*2FA on your registry access
*Don't run local package installs ad hoc
*Pin dependencies
*Have an SCA tool enforce a cool-down period on new packages
*If you use an AI coding tool, tell it to scan your manifest every time it's updated via an MCP server
*2FA on your registry access
*Don't run local package installs ad hoc