Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
mplewis
19 days ago
|
parent
|
context
|
favorite
| on:
Dependabot version updates introduce default packa...
OK, so it looks like you've still added suspicious code to your package.
drdexebtjl
19 days ago
[–]
You can make it much less suspicious. In particular, if you can compromise the package publishing process, and not just pushes to main, you can add your malicious code to binary artifacts, not to the source code.
Consider applying for YC's Fall 2026 batch!
Applications
are open till July 27.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: