Conversation

Or they should have done the due diligence themselves. Blindly upgrading to a new version of the library from a different maintainer was their choice. How were they even verifying the sources? Doesn't sound like anything was signed, and an account takeover could have done this.
2
Replying to and
so I think if NPM encourages semver upgrades then I'm not sure I want to blame people for "blindly upgrading", but I'm not sure I feel comfortable putting the responsibility on the previous maintainer to maintain all of their software, for free, forever
2
2
Show replies