Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Their build chain, CI environment, server...


npm ci wouldn't trigger this, it doesn't pick up newly published package versions. I suppose if you got a PR from Dependabot updating you to the compromised package, and happened to merge it within the window of vulnerability, then you'd get hit, but that will likewise not affect all that many developers. Or if you'd configured Dependabot to automatically merge all updates without review; I'm not sure how common that is.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: