[pnpm v11 릴리즈

pnpm v11이 릴리즈되었습니다. 주요 변경 사항으로는 Node.js 22+ 필수 지원, 공급망 보호 기능의 기본 활성화, 빌드 관련 설정의 통합(allowBuilds), 글로벌 설치 격리, SQLite 기반 스토어 인덱스 도입, 네이티브 퍼블리시 명령어 지원, 그리고 .npmrc 설정의 역할 제한 등이 포함됩니다. 특히 보안 강화와 성능 최적화에 초점을 맞춘 업데이트입니다.

https://news.hada.io/topic?id=29097

#pnpm #nodejs #javascript #packagemanager #supplychainsecurity

pnpm v11 릴리즈 | GeekNews

공급망 보호(Supply-chain protection) 기본 활성화: 보안 강화를 위해 minimumReleaseAge 기본값이 1440(1일)으로 설정됩니다. (새로 배포된 패키지는 24시간이 지나야 설치 가능) 또한 blockExoticSubdeps가 기본적으로 true가 됩니다.Node.js 22+ 필요: 이제 Node.js 22 버전 이상이 필수입

GeekNews

Dear people at @packagist:

Add multi-auth bearer for packages under the same domain for #ComposerPHP.

Thank you.

#Programming #PHP #FOSS #OSS #OpenSource #Coding #Code #SoftwareDevelopment #PackageManager #WebDevelopment #WebDev

PyPI Package elementary-data Compromised to Steal Developer Data

A malicious release of the popular elementary-data package on PyPI, which has over 1.1 million monthly downloads, allowed an attacker to steal developer data through a sneaky backdoor. This widely-used open-source tool for data observability in dbt pipelines became a prime target for the secrets-stealing campaign.

https://osintsights.com/pypi-package-elementary-data-compromised-to-steal-developer-data?utm_source=mastodon&utm_medium=social

#OpensourceCompromise #SupplyChain #PackageManager #Pypi #DataObservability

PyPI Package elementary-data Compromised to Steal Developer Data

Learn how the elementary-data package on PyPI was compromised to steal developer data and take immediate action to secure your open-source components now.

OSINTSights

Hey y'all

The #XeroLinux Package Manager is ready for testing. I removed hard dependency on our Distro making it work on any Arch-based Distro (with limitations).

Feel free to test and report any issues via Github. Will try my best.

https://github.com/xerolinux/xPackageManager

#FOSS #Linux #OpenSource #ArchLinux #PackageManager

PHP Composer Flaws Expose Code Execution Risk, Prompting Patches

Critical flaws in PHP Composer, a popular package manager, leave countless websites vulnerable to code execution attacks - but fortunately, patches have been released to swiftly mitigate this risk. If exploited, these high-severity vulnerabilities could allow hackers to execute arbitrary commands, putting entire…

https://osintsights.com/php-composer-flaws-expose-code-execution-risk-prompting-patches?utm_source=mastodon&utm_medium=social

#PhpComposer #CodeExecution #PackageManager #CommandInjection #VulnerabilityManagement

PHP Composer Flaws Expose Code Execution Risk, Prompting Patches

PHP Composer flaws expose code execution risk; apply patches now to prevent arbitrary command execution and secure your systems with urgent Composer updates today.

OSINTSights

Made a skill for this! ❤️ Hope it helps!

https://github.com/MrWillCom/ni-skill

@antfu

#ni #packagemanager #ai #skills

GitHub - MrWillCom/ni-skill

Contribute to MrWillCom/ni-skill development by creating an account on GitHub.

GitHub

AI coding agents often use improper package manager. And it is annoying to explicitly mention this problem in every project.

ni sounds like a one-size-fits-all solution that perfectly fits my need.

https://github.com/antfu-collective/ni

#ni #packagemanager #nodejs #ai

GitHub - antfu-collective/ni: 💡 Use the right package manager

💡 Use the right package manager. Contribute to antfu-collective/ni development by creating an account on GitHub.

GitHub

Okay okay. That's that. I'm converted. It's uv all the way.

Not just because of the speed though. It uses the best ideas of poetry and Pipenv, both of which I've used and the latter I've depended on for the past 4-ish years.

#python #python-uv #PackageManager