Recent @tanstack.com packages are compromised as per www.stepsecurity.io/blog/mini-sh... And yet @github.com just had dependabot open a PR updating my packages to the compromised and unlisted versions. That's absolutely wild and should never happen.
0 likes 0 replies
?