Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Florian Schmidt
Florian Schmidt
@schmidt_fu@mstdn.social  ·  activity timestamp 2 weeks ago
The New Oil
The New Oil
@thenewoil@mastodon.thenewoil.org  ·  activity timestamp 2 weeks ago

Hackers can bypass #npm’s #ShaiHulud defenses via #Git dependencies

https://www.bleepingcomputer.com/news/security/hackers-can-bypass-npms-shai-hulud-defenses-via-git-dependencies/

#cybersecurity

RE: https://mastodon.thenewoil.org/@thenewoil/115965296916113082

At this point, would it be entirely wrong to treat #npm like #rsh?

"It's on board for legacy reasons, but inherently insecure and should never be used in productive environments."
#ShaiHulud #PackageGate

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct