|
|
|
|
|
by mirashii
2899 days ago
|
|
For one, they've marked the issue as resolved before they've completed any forensic analysis to discover if additional compromised packages were uploaded with stolen credentials during the window in which they weren't revoked. This gives the false sense that its safe to install packages again. |
|