You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: '"No way to prevent this" say users of only language where this regularly happens'
51
-
date: {{.Date}}
52
-
series: "no-way-to-prevent-this"
53
-
type: blog
54
-
hero:
55
-
ai: "Photo by Andrea Piacquadio, source: Pexels"
56
-
file: sad-business-man
57
-
prompt: A forlorn business man resting his head on a brown wall next to a window.
58
-
---
59
59
60
-
In the hours following the release of [{{.CVE}}]({{.CVELink}}) for the project [{{.Project}}]({{.ProjectLink}}), site reliability workers
61
-
and systems administrators scrambled to desperately rebuild and patch all their systems to fix {{.Summary}}. This is due to the affected components being
62
-
written in C{{if .CPlusPlus}}++{{end}}, the only programming language where these vulnerabilities regularly happen. "This was a terrible tragedy, but sometimes
63
-
these things just happen and there's nothing anyone can do to stop them," said programmer {{.Name}}, echoing statements
64
-
expressed by hundreds of thousands of programmers who use the only language where 90% of the world's memory safety vulnerabilities have
65
-
occurred in the last 50 years, and whose projects are 20 times more likely to have security vulnerabilities. "It's a shame, but what can
66
-
we do? There really isn't anything we can do to prevent memory safety vulnerabilities from happening if the programmer doesn't want to
67
-
write their code in a robust manner." At press time, users of the only programming language in the world where these vulnerabilities
68
-
regularly happen once or twice per quarter for the last eight years were referring to themselves and their situation as "helpless."
title: '"No way to prevent this" say users of only language where this regularly happens'
3
+
date: {{.Date}}
4
+
series: "no-way-to-prevent-this"
5
+
type: blog
6
+
hero:
7
+
ai: "Photo by Andrea Piacquadio, source: Pexels"
8
+
file: sad-business-man
9
+
prompt: A forlorn business man resting his head on a brown wall next to a window.
10
+
---
11
+
12
+
In the hours following the release of [{{.CVE}}]({{.CVELink}}) for the project [{{.Project}}]({{.ProjectLink}}), site reliability workers
13
+
and systems administrators scrambled to desperately rebuild and patch all their systems to fix {{.Summary}}. This is due to the affected components being
14
+
written in C{{if.CPlusPlus}}++{{end}}, the only programming language where these vulnerabilities regularly happen."This was a terrible tragedy, but sometimes
15
+
these things just happen and there's nothing anyone can do to stop them," said programmer {{.Name}}, echoing statements
16
+
expressed by hundreds of thousands of programmers who use the only language where 90% of the world's memory safety vulnerabilities have
17
+
occurred in the last 50 years, and whose projects are 20 times more likely to have security vulnerabilities."It's a shame, but what can
18
+
we do? There really isn't anything we can do to prevent memory safety vulnerabilities from happening if the programmer doesn't want to
19
+
write their code in a robust manner." At press time, users of the only programming language in the world where these vulnerabilities
20
+
regularly happen once or twice per quarter for the last eight years were referring to themselves and their situation as "helpless."
title: '"No way to prevent this" say users of only package manager where this regularly happens'
3
+
date: 2026-05-21
4
+
series: "no-way-to-prevent-this"
5
+
type: blog
6
+
hero:
7
+
ai: "Photo by Andrea Piacquadio, source: Pexels"
8
+
file: sad-business-man
9
+
prompt: A forlorn business man resting his head on a brown wall next to a window.
10
+
---
11
+
12
+
In the hours following the news that [art-template](https://github.com/goofychris/art-template) fell
13
+
victim to a supply chain attack via NPM, developers and systems administrators
14
+
scrambled ensure all of their projects were unaffected from a supply chain attack where attackers have controlled the repository since 2025 and are using it to load unauthorized JavaScript from third party domains, including but not limited to Baidu Analytics.
15
+
This is is due to the affected dependencies being distributed via
16
+
[NPM](https://www.npmjs.com), the only package manager where these supply-chain
17
+
attacks regularly happen. "This was a terrible tragedy, but sometimes these
18
+
things just happen and there's nothing anyone can do to stop them," said
19
+
programmer Mrs. Macy Von, echoing statements expressed by hundreds of thousands of
20
+
programmers who use the only package manager where 90% of the world's
21
+
supply-chain attacks have occurred in the last decade, and whose projects are
22
+
20 times more likely to fall victim to supply chain attacks. "It's a shame, but
23
+
what can we do? There really isn't anything we can do to prevent supply-chain
24
+
attacks from happening if the maintainers don't want to secure access to their
25
+
accounts in a robust manner". At press time, users of the only package manager
26
+
in the world where these vulnerabilities regularly happen once or twice per
27
+
week for the last year were referring to themselves and their situation as
28
+
"helpless".
29
+
30
+
For more information, please see upstream documentation published by
31
+
art-template at the following link: [2026-art-template](https://github.com/aui/blog/issues/3).
0 commit comments