7 ms·
Software downloaded 30k times from PyPI ransacked developers’ machines
- raxxorrax 5y agoWhile this is a logistical problem and people generally don't check code in the dependency tree, I already fear the security mechanisms that might spawn from this.
- Engineering-MD 5y agoDid you have anything specific in mind?
- 0des 5y agostdlib or die. /me flashes obscure gang insignia
- remram 5y agocrev is an open-source framework trying to fix this, using a web-of-trust approach to reviews: https://github.com/crev-dev/ https://github.com/crev-dev/ Currently only available for Cargo, Rust's package manager, but more integrative are being developed.
- pfbtgom 5y agoWith the release of GitHub’s Copilot, I wonder how far we are from ML identification of malicious repositories.