cyrano@piefed.social to Technology@lemmy.worldEnglish · 8 个月前Shai-Hulud Returns: Over 300 NPM Packages Infectedhelixguard.aiexternal-linkmessage-square13fedilinkarrow-up182arrow-down13file-text
arrow-up179arrow-down1external-linkShai-Hulud Returns: Over 300 NPM Packages Infectedhelixguard.aicyrano@piefed.social to Technology@lemmy.worldEnglish · 8 个月前message-square13fedilinkfile-text
minus-squarefubarx@lemmy.worldlinkfedilinkEnglisharrow-up2·edit-28 个月前That is pretty evil. Without signing attestation (both developer and code) there will be no way to find out who was responsible and stop the propagation. This will happen again. Edit: there have been attempts like https://docs.npmjs.com/trusted-publishers, but that hasn’t fixed the problem.
That is pretty evil.
Without signing attestation (both developer and code) there will be no way to find out who was responsible and stop the propagation. This will happen again.
Edit: there have been attempts like https://docs.npmjs.com/trusted-publishers, but that hasn’t fixed the problem.