6 ms·
I think that volunteers (some of them maybe paid) should check the validity of code, at least for projects over 10-100k downloads. In case of crates.io (Rust),
by megumax 5y ago
I think that volunteers (some of them maybe paid) should check the validity of code, at least for projects over 10-100k downloads.
In case of crates.io (Rust), there is cargo-crev[1].
Also, npm should popularize 2FA.
[1]https://web.crev.dev/rust-reviews/ https://web.crev.dev/rust-reviews/
- m4rtink 5y agoSay, like package maintainers do for major Linux distributions ?