11 ms·
To be fair, the kind of programmer who would include an infected repo is almost everyone. Many infected repos have no indicators except for username to help you
by mgii 3y ago
To be fair, the kind of programmer who would include an infected repo is almost everyone. Many infected repos have no indicators except for username to help you notice without a careful examination, especially in niche repos. When you have to move fast, it's natural to make such mistakes.
- cogman10 3y agoFurther, transitive dependencies are a real risk. If A depends on B depends on C depends on D depends on E depends on F, and F is compromised which the author of E does not catch, everyone depending on any of the deps in the chain are at risk. It's why the JavaScript ecosystem of micro packages is absolutely insane. If someone infected isEven, they'd have a blast radius of 90% of JavaScript devs. It's much like having a single password protecting everything. JavaScript has way too many of these high value packages that find their way into every modern JavaScript project.
- deleted 3y ago[deleted]