Skip to main content
devlead u/devlead avatar

devlead

u/devlead

Feed options
Hot
New
Top
View
Card
Compact

r/dotnet icon

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions
r/dotnet

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions

Does anyone use file-based apps?

devlead
commented

Yes use it daily, for testing stuff, CI/CD orchestration, written custom SDKs to easily get going with just a line at the top.


r/dotnet icon

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions
r/dotnet

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions

NuGet gallery supply chain attack?

devlead
replied to bolorundurowb

Yip, never click on anything unless verified through another channel.


r/dotnet icon

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions
r/dotnet

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions

NuGet gallery supply chain attack?

devlead
replied to OTonConsole

If trying to figure something out, or maybe a CoPilot prompt gone wild with the NuGet & Playwright MCP servers 😎


r/dotnet icon

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions
r/dotnet

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions

NuGet gallery supply chain attack?

devlead
replied to Myselfs1977

Don't think it has anything to do with popularity per say, colleagues with packages with just hundreds of downloads gotten request too. So feels more like someone is crawling the index.


r/dotnet icon

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions
r/dotnet

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions

NuGet gallery supply chain attack?

devlead
replied to _f0CUS_

Weirdly they are not requesting access to your packages(don't think you can that), they're requesting to make you owner of THEIR package and org.


r/dotnet icon

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions
r/dotnet

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions

NuGet gallery supply chain attack?

devlead
replied to Myselfs1977

Yip, that's exactly what one should do 👍


r/dotnet icon

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions
r/dotnet

.NET Community, if you are using C#, VB.NET, F#, or anything running with .NET... you are at the right place!


Weekly visitors Weekly contributions

NuGet gallery supply chain attack?

devlead
replied to andrerav

We're probably talking of thousands of requests, multiple .NET Foundation maintainers, MVPs and colleagues of mine have gotten same requests.

I would've thought there were some kind of rate limits in place, if not, I'm sure there will be after this incident.


NuGet gallery supply chain attack?
r/csharp icon
r/csharp

All about the object-oriented programming language C#.


Weekly visitors Weekly contributions
NuGet gallery supply chain attack?
NuGet gallery supply chain attack?

There seems to be an ongoing supply chain attack or suspicious activity on NuGet.org, where a user called darklord is trying to gain legitimacy or something by sending thousands of become owner of their packages requests, don't accept, report to NuGet.org.

upvotes comments