NPM package compromised by author: erases files on RU / BY computers on install
1–10 of 188 posts
Re: NPM package compromised by author: erases files on RU / BY computers on install
#2Re: NPM package compromised by author: erases files on RU / BY computers on install
#3Quoted post unavailable.
I was myself hit by the issue, unfortunately, and I strongly believe that weaponising open-source is not how things should be done, so I decided to post. An attempt to bring this into limelight, if you wish
This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on
Re: NPM package compromised by author: erases files on RU / BY computers on install
#4Quoted post unavailable.
I rarely visit HN and mostly lurk here, not sure what you're trying to point out. I was myself hit by the issue, unfortunately, and I strongly believe that weaponising open-source is not how things should be done, so I decided to post. An attempt to bring this into limelight, if you wish This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on
Sorry to hear you were impacted by this. Software supply chain challenges are copious, unwieldy, and everywhere.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#5One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole.
FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container running with root permissions.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#6Re: NPM package compromised by author: erases files on RU / BY computers on install
#7I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…
Re: NPM package compromised by author: erases files on RU / BY computers on install
#8Re: NPM package compromised by author: erases files on RU / BY computers on install
#9Earlier quoted context omitted.
I rarely visit HN and mostly lurk here, not sure what you're trying to point out. I was myself hit by the issue, unfortunately, and I strongly believe that weaponising open-source is not how things should be done, so I decided to post. An attempt to bring this into limelight, if you wish This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on
I wasn’t suggesting any nefarious intent, only that this was the topic that made you go “Today is the day I post.” Sorry to hear you were impacted by this. Software supply chain challenges are copious, unwieldy, and everywhere.
Oh, please. The only thing missing was to accuse asn007 of being a "Russian troll", although I suppose you realized that that would not be appropriate in this case.
Just own up to your apology.
Re: NPM package compromised by author: erases files on RU / BY computers on install
#10I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…
it isn't going to stop Putin but it could negatively impact normal people. in no universe will the handful of Russian programmers impacted by this rise up and overthrow their government. but they will be forced to work extra hours cleaning up any damage this caused to their system. This is really lame virtue signalling that only harms fellow workers because their government is terrible.