Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
squidsoup
70 days ago
|
parent
|
context
|
favorite
| on:
Postmortem: TanStack NPM supply-chain compromise
This was a GitHub Actions hack, nothing related to publishing on npm was compromised.
rdg1991
70 days ago
[–]
No way to prevent this, says only CI platform (owned by the same company who owns the package manager) where this regularly happens.
Consider applying for YC's Fall 2026 batch!
Applications
are open till July 27.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: