schnurrito@discuss.tchncs.de to Cybersecurity@sh.itjust.worksEnglish · 18 hours agoDozens of Red Hat packages backdoored through its official NPM channelarstechnica.comexternal-linkmessage-square17fedilinkarrow-up194arrow-down12cross-posted to: news@lemmy.linuxuserspace.show
arrow-up192arrow-down1external-linkDozens of Red Hat packages backdoored through its official NPM channelarstechnica.comschnurrito@discuss.tchncs.de to Cybersecurity@sh.itjust.worksEnglish · 18 hours agomessage-square17fedilinkcross-posted to: news@lemmy.linuxuserspace.show
minus-squareFizz@lemmy.nzlinkfedilinkEnglisharrow-up6arrow-down2·16 hours agoI’m not familiar with npm but why is this always NPM? Is it a specific issue they have?
minus-squareBoofStroke@sh.itjust.workslinkfedilinkEnglisharrow-up27·16 hours agoIt’s a “package manager” that has zero integrity checks built in. Web devs also love it. Nice combination.
I’m not familiar with npm but why is this always NPM? Is it a specific issue they have?
It’s a “package manager” that has zero integrity checks built in. Web devs also love it. Nice combination.
Culture problem imo.