Kutholwe imitapo yolwazi emibili eyingozi kuhla lwemibhalo lwamaphakheji we-PyPI Python

Kumkhombandlela wephakheji wePython iPyPI (Python Package Index) kutholakele amaphakheji anonya "I-python3-dateutil"Futhi"i-jeIlyfish", ezilayishwe ngumbhali oyedwa u-olgired2017 futhi zafihlwa njengamaphakheji adumile "dateutil"Futhi"i-jellyfish" (okuhlukaniswa ukusetshenziswa kophawu "Mina" (i) esikhundleni sika-"l" (L) egameni). Ngemva kokufaka amaphakheji ashiwo, okhiye bokubethela nedatha eyimfihlo yomsebenzisi etholwe ohlelweni ithunyelwe kuseva yomhlaseli. Amaphakheji ayinkinga manje asekhishiwe kuhla lwemibhalo lwe-PyPI.

Ikhodi enonya ngokwayo ibikhona kuphakheji ye-"jeIlyfish", futhi iphakheji ye-"python3-dateutil" iyisebenzise njengokuncika.
Amagama akhethwe ngokusekelwe kubasebenzisi abanganakile abenze amaphutha lapho besesha (ukuthayipha). Iphakheji eliyingozi elithi “jeIlyfish” lalayishwa esikhathini esingangonyaka odlule, ngoDisemba 11, 2018, futhi alizange libonwe. Iphakheji elithi "python3-dateutil" lalayishwa ngoNovemba 29, 2019 futhi ezinsukwini ezimbalwa kamuva lavusa izinsolo phakathi komunye wonjiniyela. Ulwazi ngenani lokufakwa kwamaphakheji anonya alunikezwanga.

Iphakethe le-jellyfish lifake nekhodi elande uhlu “lwamahashi” endaweni yokugcina esekelwe ku-GitLab. Ukuhlaziywa komqondo wokusebenza ngalawa “mahashi” kubonise ukuthi aqukethe iskripthi esifakwe ikhodi kusetshenziswa umsebenzi we-base64 futhi wethulwa ngemva kokuqoshwa. Iskripthi sithole okhiye be-SSH ne-GPG ohlelweni, kanye nezinye izinhlobo zamafayela asuka kuhla lwemibhalo lwasekhaya kanye nemininingwane yamaphrojekthi we-PyCharm, sabe sesizithumela kuseva yangaphandle esebenza kungqalasizinda yefu ye-DigitalOcean.

Source: opennet.ru

Engeza amazwana