@lupyuen Yeah, I saw another post about this...are companies really just pulling software direct from public repositories? I mean, your risk profile is your own, but it's not even that hard to set up an artifactory or nexus and block retrieval of your internal packages. This is a known thing. So, if your company gets hacked this way, it's kinda your own fault.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.