Hacker News new | ask | show | jobs
by nradov 490 days ago
I assume there is also a black market for mature GitHub accounts. So you won't necessarily know if the maintainer is now a different person.
1 comments

Good point.

Also, where would the information be stored? If it was in the repo itself (as metadata) then the malicious maintainer could just not update it ...