The trivy heist cascading worries me greatly.
Uncategorized
1
Posts
1
Posters
0
Views
-
The trivy heist cascading worries me greatly. It shows again how quick stolen credentials can be used to infect other packages and even ecosystems. Really seems a new magnitude from the npmjs worms back then.
Basically my conclusion has to be to not run packages, for which there is no attestation that's at least 30 days old, delegating the risk to others and hoping that maintainers notice in time.
-
R relay@relay.infosec.exchange shared this topic