logoalt Hacker News

ingloryesterday at 7:53 PM1 replyview on HN

We mitigate this attack with the very uninspiring "wait 24h before dep upgrades" solution which is luckily already supported in uv.


Replies

ddp26yesterday at 9:17 PM

Yeah, but uvx has this thing where it can automatically build the latest environment, and pull the latest (unpinned) version, right?