Lemmy.one
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
☆ Yσɠƚԋσʂ ☆@lemmy.ml to General Programming Discussion@lemmy.mlEnglish · 9 hours ago

‘No Way To Prevent This,’ Says Only Package Manager Where This Regularly Happens

kevinpatel.xyz

external-link
message-square
0
fedilink
  • cross-posted to:
  • programmer_humor@programming.dev
  • programmerhumor@lemmy.ml
  • programming@programming.dev
  • hackernews@lemmy.bestiver.se
19
external-link

‘No Way To Prevent This,’ Says Only Package Manager Where This Regularly Happens

kevinpatel.xyz

☆ Yσɠƚԋσʂ ☆@lemmy.ml to General Programming Discussion@lemmy.mlEnglish · 9 hours ago
message-square
0
fedilink
  • cross-posted to:
  • programmer_humor@programming.dev
  • programmerhumor@lemmy.ml
  • programming@programming.dev
  • hackernews@lemmy.bestiver.se
SAN FRANCISCO, CA - In the wake of a devastating supply chain attack in the npm registry that left millions of enterprise applications compromised and billions of user records exposed, developers across the JavaScript ecosystem expressed deep sorrow today, lamenting that such a crisis was completely unavoidable. “It’s a shame, but what can you do? This is just the price of building modern web apps,” said Senior Frontend Engineer Mark Vance, echoing the sentiments of a community that completely relies on a 40-level-deep nested tree of unvetted packages maintained by pseudonymous strangers to capitalize a single string. “There’s absolutely no way to foresee or prevent someone from taking over a long-abandoned utility package and injecting a crypto-miner into every production build in the world. It’s just an act of nature.”
alert-triangle
You must log in or # to comment.

General Programming Discussion@lemmy.ml

programming@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programming@lemmy.ml

A general programming discussion community.

Rules:

  1. Be civil.
  2. Please start discussions that spark conversation

Other communities

  • !python@lemmy.ml
  • !powershell@lemmy.ml
  • !julia@lemmy.ml
  • !iosprogramming@lemmy.ml

Systems

  • !rust@lemmy.ml
  • !cpp@lemmy.ml
  • !c_programming@lemmy.ml

Functional Programming

  • !haskell@lemmy.ml
  • !fpcomplete@lemmy.ml

Also related

  • !opensource@lemmy.ml
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 22 users / day
  • 53 users / week
  • 215 users / month
  • 730 users / 6 months
  • 93 local subscribers
  • 9.92K subscribers
  • 644 Posts
  • 1.17K Comments
  • Modlog
  • mods:
  • Evan@lemmy.ml
  • Restioson@lemmy.ml
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org