I had been using package. json version keepers for quite some time but after the big supply chain attack i thought they would be the perfect place to add in some security. The idea is just to provide the latest package number x days old.
Source: [Hacker News](https://marketplace.visualstudio.com/items?itemName=about14sheep.tinynpm)