3 ms·
I think in most cases the threat is not about the authors bad intentions. Take Guzzle as an example, it recently had a very serious flaw that allowed anyone to
by EJTH 10y ago
I think in most cases the threat is not about the authors bad intentions. Take Guzzle as an example, it recently had a very serious flaw that allowed anyone to set a custom proxy for all HTTP requests using it, this could of course be used to leak information about backend APIs, mitm the requests etc.
All of this happened because Guzzle devs followed some obscure standard that required you to set the proxy by the env var HTTP_PROXY. And another "standard" putting any headers set in a request as env var variables prefixed with HTTP_*
I guess what I am trying to say here is that eventhough an author may have good intentions, it can still cause bad things to happen. You should always scrutinize dependencies, but I think most rarely do.