build1 publisher
A predictable pnpm cache key carried fork code into TanStack's npm release workflow
TanStack's postmortem says 84 malicious versions went out across 42 packages on 2026-05-11 with no npm token stolen, because a release job restored a cache that an untrusted pull_request_target build had written.
Publishers:tanstack.com
Reality
- Evidence68
- Adoption45
- Hype gap+6
- Incentives65
- Confidence58