Reddit
fsnotify Go Library Raises Supply Chain Alarms — 321K Dependent Projects Affected by Maintainer Access Changes
The widely-used Go filesystem notification library fsnotify (10,700+ stars, 321,000+ dependent projects) triggered supply chain security concerns after maintainer Yasuhiro Matsumoto (mattn) was removed from the GitHub organization, posting that even the original author had been removed. Socket.dev researchers flagged the pattern — recent releases, changed maintainer access, deleted public posts — as matching supply chain compromise signatures. Investigations found no malicious code, but the incident highlights how critical infrastructure depends on fragile maintainer trust.
Source
↳ Follow the thread