logoalt Hacker News

0fflineuseryesterday at 5:45 PM1 replyview on HN

The nixpkg from unstable seems to be infected as it s 2.6.2 https://search.nixos.org/packages?channel=unstable&include_h...


Replies

minkowskiyesterday at 6:00 PM

Nixpkgs uses the GitHub source, not the PyPI dist, for lightning; unclear to me from the advisory whether this should also be considered compromised.

show 2 replies