Skip to content

Yanking v15 is suspicious behaviorΒ #1785

@quentindemetz

Description

@quentindemetz

Hello,

I noticed this morning that v15 has been yanked and I can't find the explanation. This is bound to impact many users, a significant fraction of which are likely to move to the just-released v16.

This is suspicious:

  • yanking v15 is an aggressive nudge to move to v16
  • there is a very large commit which landed directly on master. It did not go through a pull request and subsequent code review; the summary is AI-generated.

This looks fishy in the light of recent NPM package compromises (1 and 2).

We'll be holding off from upgrading to v16 for a couple days/weeks until this clears up

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions