▲ 80 ▼ Shai-Hulud Returns: Over 300 NPM Packages Infected (helixguard.ai) submitted 9 months ago by cyrano@piefed.social to c/technology@lemmy.world 12 comments fedilink hide all child comments cross-posted from: https://lemmy.bestiver.se/post/758000 Comments
[–] SnoringEarthworm@sh.itjust.works 46 points 9 months ago* (last edited 9 months ago) (1 child) "No Way To Prevent This" Says Only Package Manager Where This Regularly Happens* *This is a joke about gun violence. permalink fedilink source hideshow 2 child comments replies: [–] InternetCitizen2@lemmy.world 15 points 9 months ago (1 child) Real question? Is it really isolated to npm or is there a few lessons others could take and discover their own vulnerabilities? permalink fedilink source parent hideshow 2 child comments replies: [–] frongt@lemmy.zip 12 points 9 months ago (1 child) It happens in python pip too. permalink fedilink source parent hideshow 2 child comments replies: [–] Eldritch@piefed.world 5 points 9 months ago (1 child) Arch checking in. It may happen less. But it still does. permalink fedilink source parent hideshow 2 child comments replies: [–] orclev@lemmy.world 8 points 9 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 2 child comments replies: [–] Eldritch@piefed.world 2 points 9 months ago That is fair. permalink fedilink source parent
[–] InternetCitizen2@lemmy.world 15 points 9 months ago (1 child) Real question? Is it really isolated to npm or is there a few lessons others could take and discover their own vulnerabilities? permalink fedilink source parent hideshow 2 child comments replies: [–] frongt@lemmy.zip 12 points 9 months ago (1 child) It happens in python pip too. permalink fedilink source parent hideshow 2 child comments replies: [–] Eldritch@piefed.world 5 points 9 months ago (1 child) Arch checking in. It may happen less. But it still does. permalink fedilink source parent hideshow 2 child comments replies: [–] orclev@lemmy.world 8 points 9 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 2 child comments replies: [–] Eldritch@piefed.world 2 points 9 months ago That is fair. permalink fedilink source parent
[–] frongt@lemmy.zip 12 points 9 months ago (1 child) It happens in python pip too. permalink fedilink source parent hideshow 2 child comments replies: [–] Eldritch@piefed.world 5 points 9 months ago (1 child) Arch checking in. It may happen less. But it still does. permalink fedilink source parent hideshow 2 child comments replies: [–] orclev@lemmy.world 8 points 9 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 2 child comments replies: [–] Eldritch@piefed.world 2 points 9 months ago That is fair. permalink fedilink source parent
[–] Eldritch@piefed.world 5 points 9 months ago (1 child) Arch checking in. It may happen less. But it still does. permalink fedilink source parent hideshow 2 child comments replies: [–] orclev@lemmy.world 8 points 9 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 2 child comments replies: [–] Eldritch@piefed.world 2 points 9 months ago That is fair. permalink fedilink source parent
[–] orclev@lemmy.world 8 points 9 months ago (1 child) To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place. permalink fedilink source parent hideshow 2 child comments replies: [–] Eldritch@piefed.world 2 points 9 months ago That is fair. permalink fedilink source parent