Hacker News new | ask | show | jobs
by groby_b 271 days ago
I love Obsidian dearly, but if you build an app that's only really useful with plugins, and that has a horrifyingly bad security model for plugins and little to no assurance of integrity of the plugins...

Maybe, just maybe, don't give fullmouthed advice on reducing risk in the supply chain.

1 comments

But what about VScode?
Do you hear the VSCode team talk about supply chain security?