mirror of
https://github.com/VictoriaMetrics/VictoriaMetrics.git
synced 2026-05-17 08:36:55 +03:00
Recent supply chain attacks on GitHub Actions and npm packages show the risk of pulling dependency updates too quickly: - https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise - https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan