Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> which started out as the butt of every supply chain joke

Mostly because 99% of developers knows nothing about supply chain attacks and leftpad blew up.

Both npm and rust should force 2FA. Thankfully, crates.io forces github SSO, and github will eventually force 2FA.



> Thankfully, crates.io forces github SSO.

Ouch. That must be difficult for any Rust package maintainers whose GitHub accounts were deleted a few months ago due to the Russian war sanctions.


Yes, Putin is a piece of shit, unfortunately.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: