build1 publisher
A backdoored TanStack dependency lifted the CI key that could read CrowdSec's private repositories
TanStack closed out its package compromise on May 15th, and CrowdSec learned 124 days later that the same incident had cost it a CI credential with read access to its private code. The notice came from an outside researcher.
Publishers:runtimewire.com
Reality
- Evidence46
- Adoption55
- Hype gap+12
- Incentives74
- Confidence55