26-04-2020 17:19
via
zdnet.com
Another one-line npm package breaks the JavaScript ecosystem
An update to tiny "is-promise" library impacted millions of JavaScript projects.
Read more »