<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dnaaun</title><link>https://news.ycombinator.com/user?id=dnaaun</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 08 May 2026 14:27:54 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dnaaun" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by dnaaun in "Maybe you shouldn't install new software for a bit"]]></title><description><![CDATA[
<p>Every dependency compromise  that I can remember "in the past few months" were discovered in hours, if not minutes (litllm, axios, bitwarden CLI, Checkmarx docker images, Pytorch lightning, intercom/intercom-php). What's more, the discovery of these compromises did not at all rely on whether the compromises were actively used.<p>That's why I don't understand:<p>> If everyone starts waiting a week, their exploits will wait 2 weeks</p>
]]></description><pubDate>Fri, 08 May 2026 06:32:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48059413</link><dc:creator>dnaaun</dc:creator><comments>https://news.ycombinator.com/item?id=48059413</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48059413</guid></item></channel></rss>