Supply-chain attack using invisible code hits GitHub and other repositories
arstechnica.comSmall discussion on last post (7 points, 8 comments) https://news.ycombinator.com/item?id=47374479
Small discussion on last post (7 points, 8 comments) https://news.ycombinator.com/item?id=47374479