vue-i18n reverted a PR after a suspicious GitHub account rename/delete pattern
Maintainers treated account lifecycle behavior as a possible precursor to a supply-chain attack even though the submitted code was not itself malicious
I reverted PR #2470 in vue-i18n master. There’s no malicious code in the code itself from the CVE-2025-53892 backport, but the contributor’s GitHub account went through a rename → deletion pattern, which feels like a precursor to a supply c