Hacker News new | ask | show | jobs
by mikeryan 921 days ago
Sounds like they’re publishing to npm with a GitHub action which can be done with an automation token which bypasses 2fa