4 ms·
I’m one of Homebrew’s security maintainers, and I don’t recall any contact with you. Who did you reach out to? If you have concrete concerns, please bring them
by woodruffw 19d ago
I’m one of Homebrew’s security maintainers, and I don’t recall any contact with you. Who did you reach out to?
If you have concrete concerns, please bring them to us. Vague concerns and hand-waving about “people getting hurt” isn’t appropriate or productive.
- lrvick 19d agoI had jumped into chats and a github issue as I recall, probably 7-8 years ago based on the employer I was researching it for, but would be hard to track that down now. Anyway, my tone may not be entirely constructive, but it is one of frustration as seemingly no one is taking supply chain attacks seriously anywhere I look. I am quite sure if homebrew was backdoored, it would give an attacker control of production systems of countless financial companies, defense contractors, healthcare providers, AI labs. I think it is insane they trust rando homebrew maintainers with that much power, but they do and they are probably not going to stop because they do not even understand these risks, and there are not practical alternatives to brew on MacOS. So that puts some major responsibility on the Homebrew team to either warn people to stop using it in high risk environments, or manage homebrew in a way appropriate for those environments. Stagex actually does every single thing I am recommending Homebrew do, and with a way smaller team. What we do is also nowhere near enough, but the bar is in hell.