3 ms·
LiteLLM PyPI has been compromised an hour ago, do not update
- parad0x0n 6mo agoThank you!
- rgambee 6mo agoIt's also been reported to their GitHub: https://github.com/BerriAI/litellm/issues/24512 https://github.com/BerriAI/litellm/issues/24512
- Bullhorn9268 6mo agoyeah, updated in the post
- deleted 6mo ago[deleted]
- darkteflon 6mo agoWe recently switched to pnpm, in part to guard against supply chain attacks (https://pnpm.io/supply-chain-security https://pnpm.io/supply-chain-security). Reading this got me wondering whether uv has something similar, and indeed it does appear to (https://docs.astral.sh/uv/reference/settings/#exclude-newer https://docs.astral.sh/uv/reference/settings/#exclude-newer)
- nateb2022 6mo agoWherever practical, I also recommend using devcontainers, so that in addition to breaking supply chain security, large-scale damage would require an unpatched sandbox exploit too.
- Mooshux 6mo ago[dead]
- deleted 6mo ago[deleted]