uv lock files and malware on PyPI
A potentially surprising interplay between these two systems means you might get compromised by deleted packages.
4 posts
A potentially surprising interplay between these two systems means you might get compromised by deleted packages.
Brief notes on tools we choose to use, their impacts and risks, and who bears the cost.
A short example of reverse engineering the license check for a fairly compact VS Code extension.