▲ 80 ▼ Shai-Hulud Returns: Over 300 NPM Packages Infected (helixguard.ai) submitted 10 months ago by cyrano@piefed.social to c/technology@lemmy.world 11 comments fedilink hide all child comments cross-posted from: https://lemmy.bestiver.se/post/758000 Comments
[–] SnoringEarthworm@sh.itjust.works 46 points 10 months ago* (last edited 10 months ago) (5 children) "No Way To Prevent This" Says Only Package Manager Where This Regularly Happens* *This is a joke about gun violence. permalink fedilink source hideshow 5 child comments replies: [–] InternetCitizen2@lemmy.world 15 points 10 months ago (4 children) Real question? Is it really isolated to npm or is there a few lessons others could take and discover their own vulnerabilities? permalink fedilink source parent hideshow 4 child comments replies: [–] frongt@lemmy.zip 12 points 10 months ago (3 children) It happens in python pip too. permalink fedilink source parent hideshow 3 child comments replies: [–] Eldritch@piefed.world 5 points 10 months ago (2 children) Arch checking in. It may happen less. But it still does. permalink fedilink source parent hideshow 2 child comments replies: [–] orclev@lemmy.world 8 points 10 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 1 child comment replies: [–] Eldritch@piefed.world 2 points 10 months ago That is fair. permalink fedilink source parent
[–] InternetCitizen2@lemmy.world 15 points 10 months ago (4 children) Real question? Is it really isolated to npm or is there a few lessons others could take and discover their own vulnerabilities? permalink fedilink source parent hideshow 4 child comments replies: [–] frongt@lemmy.zip 12 points 10 months ago (3 children) It happens in python pip too. permalink fedilink source parent hideshow 3 child comments replies: [–] Eldritch@piefed.world 5 points 10 months ago (2 children) Arch checking in. It may happen less. But it still does. permalink fedilink source parent hideshow 2 child comments replies: [–] orclev@lemmy.world 8 points 10 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 1 child comment replies: [–] Eldritch@piefed.world 2 points 10 months ago That is fair. permalink fedilink source parent
[–] frongt@lemmy.zip 12 points 10 months ago (3 children) It happens in python pip too. permalink fedilink source parent hideshow 3 child comments replies: [–] Eldritch@piefed.world 5 points 10 months ago (2 children) Arch checking in. It may happen less. But it still does. permalink fedilink source parent hideshow 2 child comments replies: [–] orclev@lemmy.world 8 points 10 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 1 child comment replies: [–] Eldritch@piefed.world 2 points 10 months ago That is fair. permalink fedilink source parent
[–] Eldritch@piefed.world 5 points 10 months ago (2 children) Arch checking in. It may happen less. But it still does. permalink fedilink source parent hideshow 2 child comments replies: [–] orclev@lemmy.world 8 points 10 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 1 child comment replies: [–] Eldritch@piefed.world 2 points 10 months ago That is fair. permalink fedilink source parent
[–] orclev@lemmy.world 8 points 10 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 1 child comment replies: [–] Eldritch@piefed.world 2 points 10 months ago That is fair. permalink fedilink source parent