Supply chain compromise in mistralai Python package

(github.com)

6 points | by meander_water 9 hours ago ago

3 comments

  • meander_water an hour ago ago

    This appears to be part of the same Mini Shai-Hulud campaign affecting Tanstack Router https://www.securityweek.com/tanstack-mistral-ai-uipath-hit-...

  • evilmonkey19 4 hours ago ago

    I use mistralai and their API is quite good. Luckily I like to pin the versions and upgrade manually a little bit later just in case of this kind of unfortunate events.

    • ilvez 2 hours ago ago

      Have version lock as well, but dependency resolution seems to be messed up for a time. Started unrelated upgrade action and got blocked :)