//
sign in
Post
by @danabra.mov
PostEmbed
by @danabra.mov
Record
by @jimpick.com
Record
by @atsui.org
+ new component
Post
Scary exploit. TODO: ‣ No secrets in env files ‣ Restrict sudo/SSH key access ‣ Block same-day dependency upgrades or exotic transitive dependencies ‣ Block GH workflow runs for external contributors ‣ Npm ecosystem continues to be a dumpster fire www.youtube.com/watch...
25d
Fireship
www.youtube.com
A single PR just hijacked the NPM registry...
Alexandru Nedelcu