|
|
|
|
|
by Hackbraten
810 days ago
|
|
Definitely this. I’ve been a package maintainer for a decade. I make it a habit to spot check the source code of every update of every upstream package, hoping that if many others do the same, it might make a difference. But this backdoor? I wouldn’t have been able to spot it to save my life. |
|
I do agree that it's unreasonable to review the code of the entire dependency tree, but reviewing own code thoroughly and direct dependencies casually should be the bare minimum we should expect maintainers to do.