Hacker News new | ask | show | jobs
by prmoustache 3 days ago
> And what if upstream is problematic?

The same as when you install any software on macos or windows, even proprietary ones, that may themselves depend on third party libraries.

At every stage of development there is a possibility of malicious code being introduced.