qaz@lemmy.world to Selfhosted@lemmy.worldEnglish · 1 month agoAxios JavaScript library has been compromised with malware in supply chain attackgithub.comexternal-linkmessage-square12linkfedilinkarrow-up1229arrow-down10
arrow-up1229arrow-down1external-linkAxios JavaScript library has been compromised with malware in supply chain attackgithub.comqaz@lemmy.world to Selfhosted@lemmy.worldEnglish · 1 month agomessage-square12linkfedilink
minus-squaretaco_shale032@lemmy.mllinkfedilinkEnglisharrow-up8·1 month agoI agree, I think it would be better to use something like dependabot or renovatebot so you can know of and apply security updates right away.
minus-squareEskuero@lemmy.fromshado.wslinkfedilinkEnglisharrow-up11·1 month agoAs long as the bot is not allowed to automatically merge minor version bumps in libraries…
minus-squaremagikmw@piefed.sociallinkfedilinkEnglisharrow-up3·1 month agoWell yes, one can misuse any tool.
I agree, I think it would be better to use something like dependabot or renovatebot so you can know of and apply security updates right away.
As long as the bot is not allowed to automatically merge minor version bumps in libraries…
Well yes, one can misuse any tool.