> or it is "I can trust this code".
what might be better would be some kind of trust layer built into package managers so they (optionally) only allow verified repos to be installed
what might be better would be some kind of trust layer built into package managers so they (optionally) only allow verified repos to be installed
Obviously it's hard to make a one-size-fits-all solutions, bottom line is that if you use third party code for anything serious you have to do your due diligence from a security pov, a vulnerability assessment at the bare minimum.
Lots of big companies are in fact maintaining their own versions of whole package ecosystems just to manually address any security concern, which is a crazy effort.