|
|
|
|
|
by mixedbit
134 days ago
|
|
An extension from a trusted, non anonymous developer which is released as open source is a good signal that the extension can be trusted. But keep in mind that distribution channels for browser extensions, similarly to distribution channels for most other open source packages (pip, npm, rpm), do not provide any guarantee that the package you install and run is actually build verbatim from the code which is open sourced. |
|
https://docs.npmjs.com/trusted-publishers#automatic-provenan...