Weekly roundup of package management news covering releases, security advisories, and articles. Key releases include Hex 2.5.0 with organisation-defined dependency policies, uv 0.11.25/0.11.26 with hardened tar handling and resolver improvements, npm 12.0.0-pre.2 graduating linked installs to stable, and Rust 1.96.1 fixing Cargo HTTP client issues and libssh2 CVEs. Security highlights include multiple Composer vulnerabilities (path traversal, credential leakage), four Guix daemon/client vulnerabilities, a python.org API authentication bypass, and a campaign hijacking npm and Go packages to deploy an infostealer via VS Code tasks. Articles cover Guix packages as Nix flakes, vulnerability definition theory, and Zig moving all package management out of the compiler. Research papers examine Git tag mutability undermining reproducible builds, PyPI package replication spreading vulnerabilities, and scanner evasion techniques for agent-skill malware.

5m read timeFrom nesbitt.io
Post cover image
Table of contents
Releases #Security #Articles #Papers #Elsewhere #git-pkgs #
573 Impressions