Hacker News new | ask | show | jobs
by orbz 1559 days ago
IANAL, but I suspect that it is considered unauthorized as there are many avenues in which a dependency will get updated without a user specifying this exact package and version. I think the key here is that there is clear malicious intent.