Amathala eencwadi amabini akhohlakeleyo afunyenwe kulawulo lweephakheji zePyPI Python

Kuluhlu lwePython lwephakheji yePyPI (Python Package Index) ifunyenwe iipakethe ezinobungozi "ipython3-dateutil"Kwaye"jeIlyfish", ezilayishwe ngumbhali omnye olgired2017 kwaye ziguqulwe njengeepakethe ezidumileyo "dateutil"Kwaye"jellyfish" (eyahlulwa ngokusetyenziswa kwesimboli "Mna" (i) endaweni ka "l" (L) egameni). Emva kokufaka iipakethe ezikhankanyiweyo, izitshixo zokubethela kunye nedatha eyimfihlo yomsebenzisi efunyenwe kwinkqubo ithunyelwe kumncedisi womhlaseli. Iipakethe eziyingxaki ngoku zisusiwe kulawulo lwePyPI.

Ikhowudi ekhohlakeleyo ngokwayo yayikhona kwiphakheji ye-"jeIlyfish", kwaye iphakheji ye-"python3-dateutil" isetyenziswe njengokuxhomekeka.
Amagama akhethwa ngokusekwe kubasebenzisi abangenankathalo abenze iitypos xa bekukhangelwa (ukuchwetheza). Iphakheji enobungozi "jeIlyfish" yakhutshelwa malunga nonyaka odlulileyo, ngoDisemba 11, 2018, kwaye ayizange ibonwe. Iphakheji "python3-dateutil" yafakwa ngoNovemba 29, 2019 kwaye kwiintsuku ezimbalwa kamva yavusa urhano phakathi komnye wabaphuhlisi. Ulwazi ngenani lofakelo lweepakethe ezinobungozi alunikezelwanga.

Iphakheji yejellyfish iquka ikhowudi ekhuphele uluhlu "lweehashi" kwindawo yokugcina esekelwe kwi-GitLab. Uhlalutyo lwengqiqo yokusebenza nezi "hashes" zibonise ukuba ziqulethe i-script encoded usebenzisa i-base64 function kwaye iqaliswe emva kokubhalwa kwekhowudi. Iskripthi sifumene izitshixo ze-SSH kunye ne-GPG kwinkqubo, kunye nolunye uhlobo lweefayile ukusuka kulawulo lwasekhaya kunye neziqinisekiso zeeprojekthi zePyCharm, kwaye emva koko uzithumele kumncedisi wangaphandle osebenza kwi-DigitalOcean cloud infrastructure.

umthombo: opennet.ru

Yongeza izimvo