/top/
/new/
/best/
/ask/
/show/
/job/
^
slacker news
login
about
←back to thread
NPM debug and chalk packages compromised
(www.aikido.dev)
1369 points
universesquid
| 1 comments |
08 Sep 25 15:37 UTC
|
HN request time: 0s
|
source
https://github.com/advisories/GHSA-8mgj-vmr8-frr6
Show context
martypitt
◴[
08 Sep 25 16:15 UTC
]
No.
45170121
[source]
▶
>>45169657 (OP)
#
A super quick script to check the deps in your package-lock.json file is here[0].
[0]:
https://gist.github.com/martypitt/0d50c350aa7f0fc73354754343...
replies(2):
>>45170178
#
>>45170233
#
patates
◴[
08 Sep 25 16:23 UTC
]
No.
45170233
[source]
▶
>>45170121
#
aren't these already nuked and show up in the "npm audit" command?
replies(2):
>>45170271
#
>>45170303
#
1.
martypitt
◴[
08 Sep 25 16:26 UTC
]
No.
45170271
[source]
▶
>>45170233
#
Nice - that's even better - thanks! TIL.
ID:
GO
↑