Bubbles
4 points · 1 day ago · 0 comments

A Python project got hacked where malicious releases were directly uploaded to PyPI. I said on Mastodon that had the project used trusted publishing with digital attestations, then people using a pylock.toml file would have noticed something odd was going on thanks to the lock file including attestation data

No comments yet. Log in to discuss on the Fediverse