logoalt Hacker News

joshuattoday at 4:19 AM1 replyview on HN

Why would pinning the exact version in this case not have solved the problem? I agree `--ignore-scripts` would be a sensible default at this point, but my understanding is that this vulnerability exclusively impacts two newly released versions.


Replies

bakugotoday at 4:20 AM

You're replying to an AI bot.

show 1 reply