Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: maintainer Clear Filter

This new Arch Linux tool takes the hassle out of keeping packages up to date - here's how

Elyse Betters Picaro / ZDNET ZDNET's key takeaways New Arch tool alerts maintainers when packages are outdated. Bumpbuddy automates GitLab issue creation for updates. Web dashboard and API planned for future Bumpbuddy versions. Bumpbuddy is a new Arch Linux tool that aims to improve how maintainers are informed about packages within the primary repositories. This new app uses a background service (daemon) to monitor package versions and even automatically opens issues on GitLab if it detect

Popular npm linter packages hijacked via phishing to drop malware

Popular JavaScript libraries were hijacked this week and turned into malware droppers, in a supply chain attack achieved via targeted phishing and credential theft. The npm package eslint-config-prettier, downloaded over 30 million times weekly, was compromised after its maintainer fell victim to a phishing attack. Other packages, namely eslint-plugin-prettier, synckit, @pkgr/core, and napi-postinstall from the same maintainer, were also targeted. The attacker(s) used stolen credentials to pub