• unknownuserunknownlocation@kbin.earth
    link
    fedilink
    arrow-up
    3
    ·
    6 hours ago

    The would protect against malicious code running on the Dev’s computer (which AFAICT is the case here), but not against the code created using the infected library running on users’ computers. And honestly, seeing the regularity of supply chain attacks in recent times, I think we need to find a better way to work with supply chains going forward. Although I admittedly don’t have any solutions myself, tbh.