logoalt Hacker News

LtWorfyesterday at 9:09 AM1 replyview on HN

If they have compromised the token wouldn't that mean the developer is compromised and such access can be used to just put "curl whatever" into the build and publish that payload on pypi?


Replies

woodruffwyesterday at 1:03 PM

I don’t understand the question, sorry.

show 1 reply