3 ms·
The nixpkg from unstable seems to be infected as it s 2.6.2 https://search.nixos.org/packages?channel=unstable&include_home_manager_options=1&include_modular_se
by 0fflineuser 5mo ago
The nixpkg from unstable seems to be infected as it s 2.6.2 https://search.nixos.org/packages?channel=unstable&include_home_manager_options=1&include_modular_service_options=1&include_nixos_options=1&query=pytorch+lightning https://search.nixos.org/packages?channel=unstable&include_h...
- minkowski 5mo agoNixpkgs uses the GitHub source, not the PyPI dist, for lightning; unclear to me from the advisory whether this should also be considered compromised.
- andymcsherry 5mo agoAndy from Lightning here. Thanks for pointing that out, we are updating the CVE. Only the versions from PyPi were affected. The malicious code was not checked into the GitHub repository
- deforciant 5mo agogithub is fine, the package was only pushed into pypi directly