151.
152.
Trump Ends Tariff Exemption for Small Packages
(wired.com)
153.
Flaw in Gemini CLI coding tool could allow hackers to run nasty commands
(arstechnica.com)
154.
Supply-chain attacks on open source software are getting out of hand
(arstechnica.com)
155.
Open source repositories are seeing a rash of supply-chain attacks
(arstechnica.com)
156.
Hackers breach Toptal GitHub account, publish malicious npm packages
(bleepingcomputer.com)
157.
NPM package ‘is’ with 2.8M weekly downloads infected devs with malware
(bleepingcomputer.com)
158.
npm 'accidentally' removes Stylus package, breaks builds and pipelines
(bleepingcomputer.com)
159.
OSS Rebuild: open-source, rebuilt to last
(news.ycombinator.com)
160.
OSS Rebuild: open-source, Rebuilt to Last
(news.ycombinator.com)
161.
162.
Debcraft – Easiest way to modify and build Debian packages
(news.ycombinator.com)
163.
Arch Linux pulls AUR packages that installed Chaos RAT malware
(bleepingcomputer.com)
164.
Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
(news.ycombinator.com)
165.
North Korean XORIndex malware hidden in 67 malicious npm packages
(bleepingcomputer.com)
166.
Solving Wordle with uv's dependency resolver
(news.ycombinator.com)
168.
Ubuntu: Introducing Debcrafters
(news.ycombinator.com)
169.
Why Go Rocks for Building a Lua Interpreter
(news.ycombinator.com)
170.
uv: An extremely fast Python package and project manager, written in Rust
(news.ycombinator.com)
Today's top topics:
apple
google
android authority
zdnet
microsoft
samsung
amazon
google tv
fast company
cnet