you are viewing a single comment's thread
view the rest of the comments
[–] [S] 10 points 3 months ago

The recent attack didn’t have to do with cryptographic signatures. It was a supply chain worm, with GitHub Actions being the vector. https://snyk.io/blog/tanstack-npm-packages-compromised/

  • source
  • parent