A developer appears to have purposefully corrupted a pair of open-source libraries on GitHub and software registry npm — “faker.js” and “colors.js” — that thousands of users depend on, rendering any project that contains these libraries useless, as reported by Bleeping Computer. While it looks like color.js has been updated to a working version, faker.js still appears to be affected, but the issue can be worked around by downgrading to a previous version (5.5.3).
Bleeping Computer found that the developer of these two libraries, Marak Squires, introduced a malignant commit (a file revision on GitHub) to colors.js that adds “a new American flag...
9 new trailers you should watch this week Image: Disney
I feel like war movies all too often take the form of action films focused on big, broad, and misguided emotions like glory. …...
Spree review: in search of an audience Sundance Film Festival
Welcome to Cheat Sheet, our breakdown-style reviews of festival films, VR previews, and other special event releases…...
0 Response to "Open source developer corrupts widely-used libraries, affecting tons of projects"
Post a Comment