|
|
|
|
|
by entrope
28 days ago
|
|
It is hard to have much sympathy for someone who complains about seeing a Git commit they never made but presumably clicked "publish" for a blog post that says "a North Korea-aligned group who targets software developers specifically. Not banks. Not hospitals. Devs." Supply chain security is a huge concern nowadays, and JavaScript in config/build-chain files is a sadly long-lived threat vector against a supply chain. |
|