davel [he/him]@lemmy.ml to Programmer Humor@lemmy.mlEnglish · 1 day ago‘No Way To Prevent This,’ Says Only Package Manager Where This Regularly Happenskevinpatel.xyzexternal-linkmessage-square14fedilinkarrow-up1140arrow-down13cross-posted to: programmer_humor@programming.devprogramming@programming.dev
arrow-up1137arrow-down1external-link‘No Way To Prevent This,’ Says Only Package Manager Where This Regularly Happenskevinpatel.xyzdavel [he/him]@lemmy.ml to Programmer Humor@lemmy.mlEnglish · 1 day agomessage-square14fedilinkcross-posted to: programmer_humor@programming.devprogramming@programming.dev
minus-squaredavel [he/him]@lemmy.mlOPlinkfedilinkEnglisharrow-up8·1 day agoThe recent attack didn’t have to do with cryptographic signatures. It was a supply chain worm, with GitHub Actions being the vector. https://snyk.io/blog/tanstack-npm-packages-compromised/
The recent attack didn’t have to do with cryptographic signatures. It was a supply chain worm, with GitHub Actions being the vector. https://snyk.io/blog/tanstack-npm-packages-compromised/