logoalt Hacker News

6thbityesterday at 1:32 PM1 replyview on HN

title is bit misleading.

The package was directly compromised, not “by supply chain attack”.

If you use the compromised package, your supply chain is compromised.


Replies

dloryesterday at 4:21 PM

It's both. They got compromised by another supply chain attack on Trivy initially.