ThePlexus
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
qaz@lemmy.world to Selfhosted@lemmy.worldEnglish · 3 months ago

Axios JavaScript library has been compromised with malware in supply chain attack

github.com

external-link
message-square
12
fedilink
  • cross-posted to:
  • [email protected]
228
external-link

Axios JavaScript library has been compromised with malware in supply chain attack

github.com

qaz@lemmy.world to Selfhosted@lemmy.worldEnglish · 3 months ago
message-square
12
fedilink
  • cross-posted to:
  • [email protected]
[email protected] and [email protected] are compromised · Issue #10604 · axios/axios
github.com
external-link
more details: https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan Most likely, a maintainer's GitHub and npm accounts are compromised as these iss...
  • taco_shale032@lemmy.ml
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 months ago

    I agree, I think it would be better to use something like dependabot or renovatebot so you can know of and apply security updates right away.

    • Eskuero@lemmy.fromshado.ws
      link
      fedilink
      English
      arrow-up
      11
      ·
      3 months ago

      As long as the bot is not allowed to automatically merge minor version bumps in libraries…

      • magikmw@piefed.social
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 months ago

        Well yes, one can misuse any tool.

Selfhosted@lemmy.world

selfhosted@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don’t duplicate the full text of your blog or readme if you’re providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details.

Resources:

  • selfh.st Newsletter and index of selfhosted software and apps
  • awesome-selfhosted software
  • awesome-sysadmin resources
  • Self-Hosted Podcast from Jupiter Broadcasting

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 617 users / day
  • 3.01K users / week
  • 6.65K users / month
  • 14.3K users / 6 months
  • 1 local subscriber
  • 60.2K subscribers
  • 1.24K Posts
  • 22.5K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Loki@lemmy.world
  • CannaVet@lemmy.world
  • devve@lemmy.world
  • ayyy@sh.itjust.works
  • curbstickle@anarchist.nexus
  • curbstickle_lw@lemmy.world
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org