Hacker News new | ask | show | jobs
by lrvick 1182 days ago
If a lot of people trust code that comes from your account, then it can and will be weaponized for a supply chain attack.

If you do not have the good sense to lock up such a weapon, then please delete your account.

2 comments

Keyword: if. What little i do distribute to a few end users come from local builds through a completely separate system. The security level applied reflects this more than well.

To my (well-founded) knowledge nobody distributes my code; and if they did they'd have full responsibility. That's what "THE SOFTWARE IS PROVIDED 'AS IS'" means. You don't have to like it and you don't have to use it.

There really is no middle ground unless you develop a relation. Who says i can be trusted? Not me!

Not the case here.. and not the case for 99.99% of repos on github.