|
|
|
|
|
by teeray
1261 days ago
|
|
> anyone who isn't fetching their packages through Google's proxy will get told that whatever they're using is trying to trick them. That is exactly the detection of a poisoned module in the ecosystem. It would break builds, issues would get filed, and a new version would be released (and the malicious party may not be so lucky this time since it’s trust on anyone’s first use). |
|
But I guess it's also fairly easy to test it: just serve a slightly different version to the google's go mirror (by the user agent), and see how long until somebody complains to you about it.