@chansecodina @hyc @coderanger I see no technical solutions to defend against (1). The only solution to (1) is for users of a project to somehow pay for at least 2 people to be maintainers of the thing.
At the end of the day we are delegating trust to the project maintainers, and that one person delegated control of their system to someone else.
In reply to
Billy O'Neal
@malwareminigun@infosec.exchange
Dev at Microsoft on the vcpkg team. Former @VisualC STL maintainer. He/Him (Although I don’t care much)
infosec.exchange
Billy O'Neal
@malwareminigun@infosec.exchange
Dev at Microsoft on the vcpkg team. Former @VisualC STL maintainer. He/Him (Although I don’t care much)
infosec.exchange
@malwareminigun@infosec.exchange
·
Mar 24, 2026
0
0
0
Loading comments...