Pierre-Yves Lapersonne@programming.dev to Open Source@lemmy.ml · 8 months agoSonatype Uncovers Global Espionage Campaign in Open Source Ecosystemswww.sonatype.comexternal-linkmessage-square9linkfedilinkarrow-up185arrow-down12 cross-posted to: opensource@programming.dev
arrow-up183arrow-down1external-linkSonatype Uncovers Global Espionage Campaign in Open Source Ecosystemswww.sonatype.comPierre-Yves Lapersonne@programming.dev to Open Source@lemmy.ml · 8 months agomessage-square9linkfedilink cross-posted to: opensource@programming.dev
minus-squareAlex@lemmy.mllinkfedilinkarrow-up9·8 months agoI’ve long avoided npm but attacks on PyPi are a worry.
minus-squareghosttownenjoyer👻🌃@lemmy.mllinkfedilinkarrow-up1·8 months agoIf you are paranoid enough: Run all pypi packages in a QubesOs virtual machine I guess?
I’ve long avoided npm but attacks on PyPi are a worry.
If you are paranoid enough: Run all pypi packages in a QubesOs virtual machine I guess?