▲ | aragilar 5 days ago | |||||||
How? bubblewrap isn't something someone has randomly uploaded to npm, it has well known maintainers and a well organised release process (including package signing). Which is easier to do: upload a package to npm and get people to use it, or spend 2+ years trying to become a maintainer of bubblewrap or one of its dependencies to compromise it. | ||||||||
▲ | oulipo2 5 days ago | parent [-] | |||||||
Sure, but there's plenty of packages with well-known maintainers who get compromised... | ||||||||
|