| ▲ | LiteLLM PyPI has been compromised an hour ago, do not update(futuresearch.ai) | |||||||
| 27 points by Bullhorn9268 2 days ago | 8 comments | ||||||||
| ▲ | 2 days ago | parent | next [-] | |||||||
| [deleted] | ||||||||
| ▲ | darkteflon 2 days ago | parent | prev | next [-] | |||||||
We recently switched to pnpm, in part to guard against supply chain attacks (https://pnpm.io/supply-chain-security). Reading this got me wondering whether uv has something similar, and indeed it does appear to (https://docs.astral.sh/uv/reference/settings/#exclude-newer) | ||||||||
| ||||||||
| ▲ | rgambee 2 days ago | parent | prev | next [-] | |||||||
It's also been reported to their GitHub: https://github.com/BerriAI/litellm/issues/24512 | ||||||||
| ||||||||
| ▲ | parad0x0n 2 days ago | parent | prev | next [-] | |||||||
Thank you! | ||||||||
| ▲ | 15 hours ago | parent | prev | next [-] | |||||||
| [deleted] | ||||||||
| ▲ | Mooshux a day ago | parent | prev [-] | |||||||
[dead] | ||||||||