this post was submitted on 24 Nov 2025
71 points (96.1% liked)

Technology

77058 readers
3163 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] SnoringEarthworm@sh.itjust.works 43 points 1 day ago* (last edited 1 day ago) (1 children)

"No Way To Prevent This" Says Only Package Manager Where This Regularly Happens*

*This is a joke about gun violence.

[–] InternetCitizen2@lemmy.world 14 points 1 day ago (2 children)

Real question? Is it really isolated to npm or is there a few lessons others could take and discover their own vulnerabilities?

[–] frongt@lemmy.zip 11 points 1 day ago (1 children)

It happens in python pip too.

[–] Eldritch@piefed.world 5 points 1 day ago (1 children)

Arch checking in. It may happen less. But it still does.

[–] orclev@lemmy.world 7 points 1 day ago (1 children)

To be fair to Arch, the AUR was always advertised as a caveat emptor type thing. It never really claimed to be secure in the first place.

[–] Eldritch@piefed.world 2 points 7 hours ago
[–] nyan@lemmy.cafe 7 points 22 hours ago

Python and Ruby have both had various repo issues too.

I've never heard of anything similar with Perl, but that may partly be because applications for new developers who want to join CPAN still appear to be processed by humans, with up to a couple of weeks lag. The time inefficiency plus the language being less popular probably makes it an unattractive target.