
Feross Aboukhadijeh - Socket
devtools.fm: Developer Tools, Open Source, Software Development
00:00
The Risks of Relying on Code and Package Maintainers
This chapter explores the potential risks of relying on code and package maintainers in open source projects. It highlights cases where even trusted maintainers have made mistakes or intentionally sabotaged their own projects. The limitations of code signing as a solution and examples of malicious code found in popular packages on NPM are also discussed.
Transcript
Play full episode