Hacker News new | ask | show | jobs
by colonelxc 5057 days ago
Most code executed on my box comes from package managers, which often use code signing to make sure you're getting the right code. Other than that, we often have to depend on the reputation of the project, otherwise we would be stuck reading code all day, instead of getting work done.

The difference here is that this is not some long standing and reputable project, but instead just something that was randomly thrown up github.

tl;dr - I trust the Mozilla Foundation more than I trust jtwaleson