[–] rvz 4mo ago ↗ Not again and it is NPM once more.> Any project that installs one of these versions, directly or transitively, will pull the compromised release.Hope you have pinned your dependencies in your package.json.What a disaster.
3 comments
[ 0.25 ms ] story [ 23.3 ms ] thread> Any project that installs one of these versions, directly or transitively, will pull the compromised release.
Hope you have pinned your dependencies in your package.json.
What a disaster.