hn • r/hackernews
Comment on: OpenAI's response to the Axios developer tool compromise
I’m a web dev, I never made publicly accessible desktop app, so please forgive my ignorance, but:> At that time, a GitHub Actions workflow we use in the macOS app-signing process downloaded and executed a malicious version of Axios (version 1.14.1)So if I understand this correctly their GH Actions is free to upgrade the package just like that? Is this normal practice or it’s just shifting blame?