build1 publisher
A pull request comment triggered a trusted workflow that published ten malicious npm versions
The provenance on @7nohe/openapi-react-query-codegen was accurate about every question it was built to answer, which is why the Docker Security Dispatch reaches instead for a five-day resolution cooldown that npm ci does not apply.
Publishers:dev.to
Reality
- Evidence47
- Adoption
- Insufficient
- Hype gap+12
- Incentives72
- Confidence