2 ms·
The interesting detail from the GitHub thread is shaanmajid's observation that every legitimate v1 release had OIDC provenance attestations and the malicious on
by robshippr 6mo ago
The interesting detail from the GitHub thread is shaanmajid's observation that every legitimate v1 release had OIDC provenance attestations and the malicious one didn't, but nobody checks. Even simpler, if you're diffing your lockfile between deploys, a brand new dependency appearing in a patch release is a pretty obvious red flag without needing any attestation infrastructure.
- ncr100 6mo agoDupe comment - double submitted? https://news.ycombinator.com/item?id=47622805 https://news.ycombinator.com/item?id=47622805