The recent attack didn’t have to do with cryptographic signatures. It was a supply chain worm, with GitHub Actions being the vector. https://snyk.io/blog/tanstack-npm-packages-compromised/
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments