versionc@lemmy.world to Selfhosted@lemmy.worldEnglish · 15 days agoBitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply Chain Incident.community.bitwarden.comexternal-linkmessage-square79linkfedilinkarrow-up1405arrow-down13
arrow-up1402arrow-down1external-linkBitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply Chain Incident.community.bitwarden.comversionc@lemmy.world to Selfhosted@lemmy.worldEnglish · 15 days agomessage-square79linkfedilink
minus-squareEinskjaldi@lemmy.worldlinkfedilinkEnglisharrow-up1·13 days agoWhat about using pip just to download basic common libraries for offline use?
minus-squareEinskjaldi@lemmy.worldlinkfedilinkEnglisharrow-up1·12 days agoBecause they could be changed or have something sneak in the library?
minus-squarequick_snail@feddit.nllinkfedilinkEnglisharrow-up2·12 days agoYeah, without signature checking anything that you download could change to anything else. That’s a remote code execution vuln.
What about using pip just to download basic common libraries for offline use?
Don’t do it.
Because they could be changed or have something sneak in the library?
Yeah, without signature checking anything that you download could change to anything else.
That’s a remote code execution vuln.