(no title)
timgl | 3 months ago
- posthog-node 4.18.1, 5.13.3 and 5.11.3
- posthog-js 1.297.3
- posthog-react-native 4.11.1
- posthog-docusaurus 2.0.6
We've rotated keys and passwords, unpublished all affected packages and have pushed new versions, so make sure you're on the latest version of our SDKs.
We're still figuring out how this key got compromised, and we'll follow up with a post-mortem. We'll update status.posthog.com with more updates as well.
bilalq|3 months ago
mbreese|3 months ago
twistedpair|3 months ago
Sure, it might be a little bit of noise, but if you get a notice @ 3am of an unexpected publishing, you can jump on unpublishing it.
euph0ria|3 months ago
silverlight|3 months ago
timgl|3 months ago
spiderfarmer|3 months ago
brabel|3 months ago
timgl|3 months ago
Y_Y|3 months ago
Probably even safer to not have been on the latest version in the first place.
Or safer again not to use software this vulnerable.
BowBun|3 months ago
Nearly all software you use is susceptible to vulnerabilities, whether it's malicious or enterprise taking away your rights. It's in bad taste to make a comment about "not using software this vulnerable" when the issue was widespread in the ecosystem and the vendor is already being transparent about it. The alternative is you shame them into not sharing this information, and we're all worse for it.
tclancy|3 months ago
_alternator_|3 months ago