Hacker News new | ask | show | jobs
by kelnos 268 days ago
> This latest incident was detected by an individual researcher

So that still seems fine? Presumably researchers are focusing on latest releases, and so their work would not be impacted by other people using this new pnpm option.