Elektrine lite

← Feed

@rradczewski@hachyderm.io

Post #797953

2026-03-25 07:40 UTC

The trivy heist cascading worries me greatly. It shows again how quick stolen credentials can be used to infect other packages and even ecosystems. Really seems a new magnitude from the npmjs worms back then. Basically my conclusion has to be to not run packages, for which there is no attestation that's at least 30 days old, delegating the risk to others and hoping that maintainers notice in time.

Replies (1)

  • @jay_peper@chaos.social 2026-03-25 23:12

    @rradczewski yeah, I'm really distraught about this. I want new packages as soon as possible to get fixes but I also don't want to get caught out by the impostor attacks. 30 days sound already quite dangerous in the other direction

    Open ##1343817