> SHA1-Hulud the Second Comming – Postman, Zapier, PostHog All Compromised via NPM
Should be Shai-Hulud, not SHA1-Hulud.
I'm surprised github is leaving these up.
We run it on CI for each commit/PR, and if a developer tries to commit a change that updates a JS dependency to a too recent it prevents the build from running, and so on. Basically we expect that a Supply Chain attacks on NPM would be noticed in a couple of week, and we enforce this time window to our code.
benzible•2mo ago
swsieber•2mo ago
dang•2mo ago
thih9•2mo ago
a4isms•2mo ago
neogodless•2mo ago
~6 hours ago | 430 comments
dang•2mo ago
Edit: Here's a bit of explanation for those curious. Even though the links are different, the test we use for whether to merge threads is whether they are substantially the same story vs. whether the two links will lead to substantially different discussion. In this case it's clear that it's the same discussion, so I merged them.
Since the second link has additional information, I've added it to the toptext of the original post. That way people can look at both.