Javascript is not enabled. This site can still works but it'll be more interactive when javascript is enabled.
loading...
Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
insanitybit
5 hours ago
|
on: Keyv and friends compromised in active Shai-Hulud supply chain attack
Arguably crates.io is worse. NPM has cooldowns and has for a while, it has had Trusted Publishing for longer, it has human-approved releases that separate CI/CD from actual publishing. Ruby is probably worse in every way.
reply
woodruffw
4 hours ago
|
parent
RubyGems actually adopted Trusted Publishing before both npm and crates.io. To my recollection, they were second after PyPI.
(I have no opinion about the overall security posture of these indices.)
reply
insanitybit
4 hours ago
|
root
|
parent
No build script control though.
reply
loading story #49172282