Hacker News new | ask | show | jobs
by Slackwise 4240 days ago
Generally, yes, but some package managers have code-signing support, which means if you trust the authors, you can avoid potential hijacks.

At the end of the day, though, you're always going to trust someone with something.