Hacker News
new
top
best
ask
show
job
Supply-chain attack using invisible code hits GitHub and other repositories
(
arstechnica.com
)
2 points
by
pabs3
8 hours ago
1 comment
tcbrah
8 hours ago
the fact that github still renders Private Use Area codepoints as whitespace instead of flagging them is wild tbh. like we've known about this vector since 2024 and npm/github just shrugged