logoalt Hacker News

CGamesPlayyesterday at 2:07 PM1 replyview on HN

The packages that are actually compromised are yanked, but I assume you're talking about a scenario more like log4shell. In that case, you can just disable the config to install the update, then re-enable in 7 days. Given that compromised packages are uploaded all the time and zero-day vulnerabilities are comparatively less common, I'd say it's the right call.


Replies

robertfwyesterday at 3:24 PM

`uv` has per-package overrides, I imagine there may be similar in other managers