
2025-08-04 19:51:43
Is it wrong to skip digging into a project just because it's build setup needs to install #npm first? Asking for a friend.
Is it wrong to skip digging into a project just because it's build setup needs to install #npm first? Asking for a friend.
Kleines Upsi bei #NPM: Ein Entwickler ist auf Phishing reingefallen und hat so Angreifern Zugang zu diversen Paketen verschafft. Unter Anderem so was kleines wie debug. Insgesamt haben die bekannten Pakete 2.6 Milliarden(!) Downloads pro Woche(!!).
Wie war das nochmal mit sinnvollen Signaturen und - idontknow - Passwortmanagern/2FA, was auf eine Domain gebunden ist?
There are good days in software development and then there are days like these when your brain melts onto your desk and your soul shrivels after hours of video conference calls, communications proofreading, and, the horrors of all horrors, bash and powershell scripting. #npm