4 ms·
According to the thread, as of about 30 minutes ago the malicious version has been unpublished. Despite this, it seems that a lot of high profile packages were
by aeleos 8y ago
According to the thread, as of about 30 minutes ago the malicious version has been unpublished.
Despite this, it seems that a lot of high profile packages were vulnerable to an automatic minimum version bump. There have been quite a few close calls with non packages, and at some point I feel like it will actually do some damage.
- _bxg1 8y agoThe indirect dependencies thing is a real problem, for other reasons too, because you can't control those. The peer dependency system partially solves this, but it's still an issue.