4 ms·
But npm already did the damage control and restored an older version, fixing all broken CI pipelines. What does any of this have everything to do with GitHub?
by foragerr 5y ago
But npm already did the damage control and restored an older version, fixing all broken CI pipelines.
What does any of this have everything to do with GitHub?
- JimDabell 5y agoYou know NPM isn’t the only way to install JavaScript packages, right? You can add a GitHub repository directly. Yanking the NPM package doesn’t protect people who are pulling from GitHub directly.
- cr3ative 5y agoIt's a suspicious action, so probably locking the account down until they can get in touch and confirm that's what the user wanted to do, and wasn't hacked etc. Could even be automated between npm and github, a compromise warning or similar. All conjecture though.
- A_non_e-moose 5y agoAren't npm and GH all owned by Microsoft anyway?
- miltonlaxer 5y agoYes GH and NPM are part of the same company Microsoft