←back to thread

493 points neuroo | 2 comments | | HN request time: 0.504s | source
Show context
DetroitThrow ◴[] No.45040706[source]
@dang Even though the blogpost has some helpful flavor, this GH issue seems much more direct and giving much more straightforward guidance for resolving the issue. Is it possible to change the link?
replies(3): >>45041142 #>>45042648 #>>45042787 #
JdeBP ◴[] No.45041142[source]
Credit to otterly and Hilift for finding some other better coverage than this semgrep page as well:

* https://news.ycombinator.com/item?id=45040126

* https://news.ycombinator.com/item?id=45040507

replies(1): >>45041766 #
merb ◴[] No.45041766[source]
I do not like these coverages. They always write about VSCode Extension which has basically nothing todo with the bug.

It only did run affected programs of course but it's so stupid to even talk about vscode in that case. if you used the affected nx versions you are affected no matter if you used vscode,webstorm, whatever ide of your liking. if you used a not affected nx version nothing happend no matter which vscode version you used.

replies(1): >>45042494 #
1. ramimac ◴[] No.45042494[source]
Hi! Author here who added the VSCode stat :)

I thought it was useful to include because:

* it can inform triage, if you use the extension you're more likely to be impacted * because it was VSCode, Workplace Trust actually partially mitigated this in at least 38 cases

replies(1): >>45042936 #
2. merb ◴[] No.45042936[source]
The vocoder extension does not contain any affected packages, it‘s just misleading