Javascript is not enabled. This site can still works but it'll be more interactive when javascript is enabled.
loading...
Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
woodruffw
5 hours ago
|
on: Keyv and friends compromised in active Shai-Hulud supply chain attack
RubyGems actually adopted Trusted Publishing before both npm and crates.io. To my recollection, they were second after PyPI.
(I have no opinion about the overall security posture of these indices.)
reply
insanitybit
5 hours ago
|
parent
No build script control though.
reply
woodruffw
5 hours ago
|
root
|
parent
Yep. That remains the norm with Python source distributions as well. It’s a hard thing to overcome when it’s baked deeply into packaging assumptions.
reply
loading story #49172659