(no title)
dwightgunning | 3 years ago
I took a look and the vulnerability that was exploited is warned about and described in the documentation.
> Warning > Using this option to search for packages which are not in the main repository (such as private packages) is unsafe, per a security vulnerability called dependency confusion: an attacker can claim the package on the public repository in a way that will ensure it gets chosen over the private package.
jacquesm|3 years ago