3 ms·
The exploit isn't a general risk of package management, but a weakness in scripted pull request handling. GitHub is the problem, and not for the first time (re
by flpa 5y ago
The exploit isn't a general risk of package management, but a weakness in scripted pull request handling.
GitHub is the problem, and not for the first time (remember the Homakov exploit?).
Homebrew is quite similar to FreeBSD ports, which do not have these issues. Incidentally, I find that a lot of packages in Homebrew have a very high packaging quality that puts several distributions to shame. I'm saying this as someone who had previously been suspicious of Homebrew, but then I looked at some of the packages.