Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Supply chain compromise in mistralai Python package
(opens in new tab)
(github.com)
6 points
meander_water
1mo ago
3 comments
Save
Share
3 comments
3 comments · 2 top-level
top
newest
oldest
evilmonkey19
1mo ago
· 1 in thread
I use mistralai and their API is quite good. Luckily I like to pin the versions and upgrade manually a little bit later just in case of this kind of unfortunate events.
ilvez
1mo ago
Have version lock as well, but dependency resolution seems to be messed up for a time. Started unrelated upgrade action and got blocked :)
meander_water
OP
1mo ago
This appears to be part of the same Mini Shai-Hulud campaign affecting Tanstack Router
https://www.securityweek.com/tanstack-mistral-ai-uipath-hit-...
j
/
k
navigate · click thread line to collapse