Hacker Times
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
drdexebtjl
26 days ago
|
parent
|
context
|
favorite
| on:
Dependabot version updates introduce default packa...
You can make it much less suspicious. In particular, if you can compromise the package publishing process, and not just pushes to main, you can add your malicious code to binary artifacts, not to the source code.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: