Zerush@lemmy.ml to Open Source@lemmy.ml · 2 年前Over 100,000 Infected Repos Found on GitHubapiiro.comexternal-linkmessage-square25linkfedilinkarrow-up1207arrow-down14cross-posted to: hackernews@lemmy.smeargle.fans
arrow-up1203arrow-down1external-linkOver 100,000 Infected Repos Found on GitHubapiiro.comZerush@lemmy.ml to Open Source@lemmy.ml · 2 年前message-square25linkfedilinkcross-posted to: hackernews@lemmy.smeargle.fans
minus-squareerAckAlinkfedilinkarrow-up2·2 年前If you installed the original legit package it can’t be updated with such fake one (without uninstalling and installing the bad one) as the signatures won’t match. If you initially install the bad package then yes of course.
If you installed the original legit package it can’t be updated with such fake one (without uninstalling and installing the bad one) as the signatures won’t match. If you initially install the bad package then yes of course.