minus-squaretechpeakedin1991@lemmy.mltoSelfhosted@lemmy.world•Axios JavaScript library has been compromised with malware in supply chain attacklinkfedilinkEnglisharrow-up0·1 month agoDoes disabling install scripts actually do anything though? The attack would still work if put in the code itself, no? The only difference I can see is that it would run when the project is run instead of when the package is installed. linkfedilink
minus-squaretechpeakedin1991@lemmy.mltoWorld News@lemmy.ml•The longer Trump’s war drags on, the worse the coming global food crisislinkfedilinkarrow-up0·1 month agoVeganism is quickly becoming an economic necessity. linkfedilink
Does disabling install scripts actually do anything though? The attack would still work if put in the code itself, no? The only difference I can see is that it would run when the project is run instead of when the package is installed.