News Score: Score the News, Sort the News, Rewrite the Headlines

PyPI halted new users and projects while it fended off supply-chain attack

ONSLAUGHT — Automation is making attacks on open source code repositories harder to fight. Enlarge / Supply-chain attacks, like the latest PyPI discovery, insert malicious code into seemingly functional software packages used by developers. They're becoming increasingly common.Getty Images PyPI, a vital repository for open source developers, temporarily halted new project creation and new user registration following an onslaught of package uploads that executed malicious code on any device th...

Read more at arstechnica.com

© News Score  score the news, sort the news, rewrite the headlines