En vivo · Mediastack

Noticias JavaScript

Lo último del ecosistema JS, curado en español para desarrolladores en México y Latinoamérica.

Incluye notas en inglés cuando hay poca cobertura en español.

  • Generalnet-security · EN

    Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

    Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. Dependabot malware alerts, which had run on npm data alone, now … More →The post Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited...

    Leer más →
  • Generalnet-security · EN

    GitHub Dependabot malware alerts now cover eight ecosystems

    GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s Advisory Database now ingests malware reports from OpenSSF’s malicious-packages repository, a public feed in OSV format that launched in 2023 with more than 15,000 reports and has grown daily since, covering typosquats, dependency-confusion … More →The post GitHub Dependabot malware alerts now cover...

    Leer más →