Maybe this is the kick that lang devs needed to take dependency security seriously and finally make peer review mandatory for third party packages by default. If it doesn't, I hope we continue getting kicked in the balls until we do.
Maybe this is the kick that lang devs needed to take dependency security seriously and finally make peer review mandatory for third party packages by default. If it doesn't, I hope we continue getting kicked in the balls until we do.
The root problem is "I'm using software from hundreds of authors, how do I know I can trust all of them?". And that problem is indeed unsolvable. It's not even a technology problem.
And no, peer review is not the solution. Scientific fraud is still widespread despite peer review being the standard for many decades. Granted, there may be better approaches than the Wild West that is PyPI and NPM, but this problem will never go away completely.
You will never have a theoretically perfect solution to this problem, but guess what: turns out you don't have to. Even single-reviewer systems like linux repositories have proven to be vastly more secure than this crap.
This problem is absolutely solvable and eventually it will be. I just hope they solve it the right way.
Yes? Especially if it's pulling in dependencies written by a bunch of other people because then it doesn't require malicious action by those three reputable devs, but merely negligence on their part in how those dependencies (and any updates etc. to them) are managed.
I encourage you to do more research on this topic.