←back to thread

1369 points universesquid | 1 comments | | HN request time: 0.213s | source
1. MrContent04 ◴[] No.45180414[source]
Incidents like this show how fragile the supply chain really is. One compromised maintainer account can affect thousands of projects. We need better defaults for package signing + automated trust checks, otherwise we’ll just keep repeating the same cycle.”