eicker@lemmy.world to Technology@lemmy.worldEnglish · 2 months agoMassive ChainDrop npm supply-chain attack infects more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.www.bleepingcomputer.comexternal-linkmessage-square11linkfedilinkarrow-up185arrow-down12
arrow-up183arrow-down1external-linkMassive ChainDrop npm supply-chain attack infects more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.www.bleepingcomputer.comeicker@lemmy.world to Technology@lemmy.worldEnglish · 2 months agomessage-square11linkfedilink
minus-squarexilophor@lemmy.worldlinkfedilinkEnglisharrow-up2·2 months agotbh I do feel like it’s somewhat relevant in this case since the packages that were compromised on the AUR were due to the AUR’s package transfer ability for unmaintained packages
minus-squarenibbler@discuss.tchncs.delinkfedilinkEnglisharrow-up1·2 months agoBut you still will not be notified when this changes? Admittedly the dev maintaining the aur sounds better than random person…
tbh I do feel like it’s somewhat relevant in this case since the packages that were compromised on the AUR were due to the AUR’s package transfer ability for unmaintained packages
But you still will not be notified when this changes?
Admittedly the dev maintaining the aur sounds better than random person…