> Trusting any single author is a single point of failure — eventually the author of one of the packages you depend on will get compromised and an attacker will publish a malicious package.
Thanks, this is exactly the sort of thing I had in mind when writing the "Making _ trustworthy"[0] section and exactly the sort of conversation I was hoping my post would prompt. One benefit I'm hoping to get from keeping the `_` sub-packages as simple/self-contained as possible is that that sort of supply-chain attack will be easier to spot (e.g., with a 0-dependency file, you couldn't use an attack like the event-stream incident, where a dependency was swapped out for a malicious copy – the malicious code would have to be in the repo itself).
Of course "easier to spot" ≠ "won't happen", which is where your other point comes in:
> To combat this, you need package validation by multiple independent identities. The classic ways to do this are to have multiple people sign a package using PGP
Someone else made a similar point in an r/programminglanguages comment[1] in response to part 1:
> One thing I'd like to see package managers adapt, though, is quorums for publishing. A simple majority quorum of amongst 3+ people would naturally make hacking much more difficult
Do you happen to know any details about how something like that could be put into practice? I agree that it seems like something that'd be worth investing in, as an ecosystem and would be interested in any info/thoughts other care to share.
[0]: https://raku-advent.blog/2021/12/11/unix_philosophy_without_...
[1]: https://www.reddit.com/r/ProgrammingLanguages/comments/raau0...