https://tanstack.com/blog/npm-supply-chain-compromise-postmo...
We (TanStack) just released our postmortem about this.
(We changed the URL from https://github.com/TanStack/router/issues/7383 to that above.)
thank you for maintaining this inspiring ecosystem.
I didn't see a key section of a COE: "What are we doing to make sure this can't happen again?"
Apologies if I missed it. There's some discussion of things under what could have gone better, but prevention is key, and the reports not done without it.