Hacker News new | ask | show | jobs
by mm983 1787 days ago
why don't they start a partnership with a security company like they have with a server monitor and google? many security vendors use python somewhere (1), so I'm sure there would be someone willing to cooperate. scan all packages uploaded and all updates, when there is a detection put a warning on the page and in console put a warning like "this package might contain maliscious code. continue regardless?" so that typosquatting and code hijacking is mitigated

1 https://github.com/KasperskyLab?q=&type=&language=python&sor...

https://github.com/CrowdStrike?q=&type=&language=python&sort...

https://github.com/intezer?q=&type=&language=python&sort=