fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

11K
active users

Seth Larson

lottiefiles/lottie-player on NPM just yesterday had its publishing API tokens stolen and used to publish malware.

If you're using API tokens to publish to @pypi from GitHub Actions, GitLab CI/CD, Google Cloud Build, or ActiveState: please upgrade to Trusted Publishers to prevent these sorts of attacks.

docs.pypi.org/trusted-publishe

docs.pypi.orgGetting Started - PyPI Docs