ah yes, another supply chain attack. i'm sure the maintainers will do some hand-wringing and promise to do better, while nothing actually changes.
https://www.reddit.com/user/CircumspectCapybara
replying in thread
what's the alternative, just giving up on securing our dependencies?
0
0
0
no replies yet