this post was submitted on 02 Sep 2023
23 points (70.9% liked)

Open Source

31352 readers
203 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 34 points 1 year ago

This is more about developers carelessly integrating 3rd party code into their extension without verifying if it’s malicious. People should be able to spot this if it’s a widely reviewed open source extension. At the end of the day, you have to make sure you trust the developer that they have sound programming skills and decent security knowledge to not be duped into adding code from an untrusted source just because of an offer for income.