Is the llama.cpp webui in danger from the recent npm attack?

Posted by shroddy@reddit | LocalLLaMA | View on Reddit | 11 comments

There is a new npm attack with over 400 compromised packages, and the llama.cpp webui uses npm and many packages and their dependencies which in turn has their own dependencies. Is it known if any of them are compromised as well, or does it pin all packages and dependencies down to their minor version number thoroughly enough?