8 ms·
And I run most of them inside sandbox now. Why would you let a markdown linter access your ssh keys?
by ashishb 2mo ago
And I run most of them inside sandbox now.
Why would you let a markdown linter access your ssh keys?
- qup 2mo agoBecause I'm confident nothing will happen if it does
- ashishb 2mo ago> Because I'm confident nothing will happen if it does Well, best of luck. 1. Amazon has shipped backdoored packages - https://aws.amazon.com/security/security-bulletins/AWS-2025-015/ https://aws.amazon.com/security/security-bulletins/AWS-2025-... 2. Scanners like Trivy have been compromised - https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise https://socket.dev/blog/trivy-under-attack-again-github-acti... 3. Redhat is shipping backdoored FOSS packages - https://access.redhat.com/security/vulnerabilities/RHSB-2026-006 https://access.redhat.com/security/vulnerabilities/RHSB-2026... 4. Even fake and malicious ESLint packages have been published - https://gbhackers.com/eslint-package-attack/ https://gbhackers.com/eslint-package-attack/