Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
pixl97
37 days ago
|
parent
|
context
|
favorite
| on:
Keyv and friends compromised in active Shai-Hulud ...
It doesn't need to, it just updates the code, you have the human publish.
freakynit
37 days ago
[–]
Updates should be changed to delete + publish, and either should require OTP/MFA. You don't need artificial cooldown if you add a manual, informed action in-between. All these publishes went uninformed to their maintainers.. that's the issue.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: