schnurrito@discuss.tchncs.de to Cybersecurity@sh.itjust.worksEnglish · 23 days agoDozens of Red Hat packages backdoored through its official NPM channelarstechnica.comexternal-linkmessage-square19fedilinkarrow-up1104arrow-down12cross-posted to: pulse_of_truth@infosec.pubsecops@lemmy.world
arrow-up1102arrow-down1external-linkDozens of Red Hat packages backdoored through its official NPM channelarstechnica.comschnurrito@discuss.tchncs.de to Cybersecurity@sh.itjust.worksEnglish · 23 days agomessage-square19fedilinkcross-posted to: pulse_of_truth@infosec.pubsecops@lemmy.world
minus-squareBoofStroke@sh.itjust.workslinkfedilinkEnglisharrow-up28·23 days agoIt’s a “package manager” that has zero integrity checks built in. Web devs also love it. Nice combination.
It’s a “package manager” that has zero integrity checks built in. Web devs also love it. Nice combination.
Culture problem imo.