Skip to content

Comment on Tinycolor supply chain attack post-mortemparent

Comments

You can run the exact same script locally as you do in CI, with the only difference being the addition of a 2FA prompt.

That's a good point, I would lose package provenance that way. I guess that is fine since it didn't prevent anything here.

I can look into that.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.