• fubarx@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    7 hours ago

    That is pretty evil.

    Without signing attestation (both developer and code) there will be no way to find out who was responsible and stop the propagation. This will happen again.

    Edit: there have been attempts like https://docs.npmjs.com/trusted-publishers, but that hasn’t fixed the problem.