5 ms·
github repo with only pre-compiled binaries coming from npmjs. These days anything from npmjs should already raise red flags, let alone something pre-compiled w
by sintax 11mo ago
github repo with only pre-compiled binaries coming from npmjs. These days anything from npmjs should already raise red flags, let alone something pre-compiled without sources.
- meander_water 11mo agoI think you can compile the rust core lib from source yourself - https://github.com/Shyam20001/brahma-core https://github.com/Shyam20001/brahma-core
- deleted 11mo ago[deleted]
- StellaMary 11mo agoExactly I have attached the src link in Readme file. I'm maintaining independent sources and planning to build the same for python via maturin
- mnahkies 11mo agoTbf the new trusted publishers goes a long way to improving this (not used by this package by the look of it). I migrated a few of my packages to it, and now: - publishing with an API token is forbidden, must use the specified workflow w/ OIDC auth - an explicit approval step in GitHub is required to run the publish workflow (you can also set a time delay, similar to time release safes) - provenance is generated and published Ref: https://docs.npmjs.com/trusted-publishers/ https://docs.npmjs.com/trusted-publishers/
- StellaMary 11mo agoBro the source is locked and precompiled no body even the author cannot edit with malicious binaries. Thats y people used to publish binary to ensure stability. Instead of pulling from git each time.