• delcaran@feddit.it
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 hours ago

    It’s not, it’s a problem of every package manager that do not use sources and checksums, like rust and python. Take a look at this article that does a better job then me at explaining the situation.

    • anyhow2503@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      The good news is that there already is a gold standard for supply chain security: the Go programming language.

      Lmfao