Next.js Hacker News
  • top|
  • new|
  • ask|
  • show|
  • jobs|
  • GitHub
LiteLLM PyPI has been compromised an hour ago, do not update
23 points by Bullhorn9268 17 hours ago | 4 comments
  • darkteflon
    We recently switched to pnpm, in part to guard against supply chain attacks (https://pnpm.io/supply-chain-security).

    Reading this got me wondering whether uv has something similar, and indeed it does appear to (https://docs.astral.sh/uv/reference/settings/#exclude-newer)

  • rgambee
    It's also been reported to their GitHub: https://github.com/BerriAI/litellm/issues/24512
    • Bullhorn9268
      yeah, updated in the post
  • parad0x0n
    Thank you!
Guidelines | FAQ | Support | API | Security | Lists | Bookmarklet | Legal | Apply to YC | Contact