phatg
@phatggg
software engineer, I make things, builder at @cosmology_tech
Opinions are my own
yyyyaaa.com
ID: 916940468797153280
08-10-2017 08:16:58
1,1K Tweet
148 Followers
1,1K Following
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios
This is exactly why, and completely validates everything we do at Constructive because RLS is complex and must be managed or you'll make every mistake that PlanetScale is assuming here. We solve all of these issues, and then some 🚀