3 ms·
That's why I would wait for other people to find that out, if I can't trust or audit it myself. Agreed that a brand new package from an unknown single developer
by code_duck 8y ago
That's why I would wait for other people to find that out, if I can't trust or audit it myself. Agreed that a brand new package from an unknown single developer is more risky.
As far as a trap with clever obfuscation, it sounds like any software we use could be vulnerable to that. It could be added as a patch to a seemingly routine update for any of the thousands of packages on your system.