Post #1398842
2026-03-23 20:39 UTC
@malwareminigun Presumably in a WoT world, the original maintainers would have checked who vouched for this new guy before adding them as a maintainer. Which just moves the problem from "socially engineer a project owner" to "... someone a project owner trusts, directly or indirectly". This is kind of an improvement but not in a hugely meaningful way.
Replies (1)
-
@malwareminigun@infosec.exchange 2026-03-23 20:40
@coderanger They *did*. That's how JiaTan got maintainer status on the xz project's repo.