btaf45@lemmy.worldBanned to Technology@lemmy.worldEnglish · 11 months agoHundreds of code libraries posted to NPM try to install malware on dev machinesarstechnica.comexternal-linkmessage-square33linkfedilinkarrow-up11arrow-down10
arrow-up11arrow-down1external-linkHundreds of code libraries posted to NPM try to install malware on dev machinesarstechnica.combtaf45@lemmy.worldBanned to Technology@lemmy.worldEnglish · 11 months agomessage-square33linkfedilink
minus-squareLavenderDay3544@lemmy.worldlinkfedilinkEnglisharrow-up0·11 months agoI really think every package repository should be opt in and every publisher should be required to verify their identity and along with checksum verification for the downloaded files.
I really think every package repository should be opt in and every publisher should be required to verify their identity and along with checksum verification for the downloaded files.