This website accuses common libraries of being hit by malware attacks without substantiating evidence.
Couldn't find reports of #orjson being highjacked, just this websites assertion.
The same website calls my apps vulnerable and malicious, also, doesn't exactly say why.
This site sees yanking as malicious. Kind of damned if you do/don't. What if you publish a package that is
- broken
- has a vulnerability
- and you *know* that there is 0 usage for that package because it is an app & has negligible downloadsYanking is just assumed to be a lpad attack on the ecosystem.
♡ 0 ↻ 0