Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
akuchling
4mo ago
0 comments
Share
Stray thought: adding a library the PR submitter controls would be a good starting point for an XZ/SSH-style supply chain attack: badger & threaten the maintainers to add the dependency, and then sneak something into a future library update.
0 comments
default
newest
oldest
falloutx
4mo ago
This seems like a huge red flag, there is no need to add any more dependencies to an already fully featured repo
j
/
k
navigate · click thread line to collapse