Hacker News
new
past
comments
ask
show
jobs
points
by
minkowski
19 hours ago
|
comments
by
andymcsherry
19 hours ago
|
next
[-]
Andy from Lightning here. Thanks for pointing that out, we are updating the CVE. Only the versions from PyPi were affected. The malicious code was not checked into the GitHub repository
reply
by
deforciant
19 hours ago
|
prev
|
[-]
github is fine, the package was only pushed into pypi directly
reply