Popular Go library fsnotify raises supply chain alarms after maintainer access changes

Lobsters Hottest News

Summary

The popular Go library fsnotify has raised supply chain security concerns following changes to maintainer access.

<p><a href="https://lobste.rs/s/7rpqbo/popular_go_library_fsnotify_raises">Comments</a></p>
Original Article

Similar Articles

Postmortem: TanStack npm supply-chain compromise

Lobsters Hottest

Detailed postmortem of a supply-chain attack on TanStack's npm packages involving cache poisoning, OIDC token extraction, and credential harvesting malware. All affected versions deprecated; users advised to rotate credentials.