Pierre-Yves Lapersonne@programming.dev to Open Source@lemmy.ml · 15 days agoSonatype Uncovers Global Espionage Campaign in Open Source Ecosystemswww.sonatype.comexternal-linkmessage-square3fedilinkarrow-up149arrow-down11
arrow-up148arrow-down1external-linkSonatype Uncovers Global Espionage Campaign in Open Source Ecosystemswww.sonatype.comPierre-Yves Lapersonne@programming.dev to Open Source@lemmy.ml · 15 days agomessage-square3fedilink
minus-squareAlex@lemmy.mllinkfedilinkarrow-up6·edit-215 days agoI’ve long avoided npm but attacks on PyPi are a worry.
minus-square🤗lemmyverseultrahug@lemmy.mllinkfedilinkarrow-up1·2 days agoIf you are paranoid enough: Run all pypi packages in a QubesOs virtual machine I guess?
I’ve long avoided npm but attacks on PyPi are a worry.
If you are paranoid enough: Run all pypi packages in a QubesOs virtual machine I guess?