

11·
7 days agoAs long as the bot is not allowed to automatically merge minor version bumps in libraries…
I like sysadmin, scripting, manga and football.


As long as the bot is not allowed to automatically merge minor version bumps in libraries…


You can mitigate similar attacks by editing your .npmrc
min-release-age=7 # days
ignore-scripts=true


Doesnt have a dashboard per-se for centralized administration. It has a web ui to manually create create/upload collections. I personally use it a very simplistic way and just reupload an updated .vcf file with all my contacts from time to time.
About user management, I dont know how you installed radicale but they have this docs https://radicale.org/v3.html#authentication
How? If you got hit by this you are looking at restoring the system from a safe previous version.
And the compromised versions get pulled, not superseeded by a new release, so once you rebuild you would go back to a safe version…