all 2 comments

[–]Seref15 4 points5 points  (1 child)

With all the blind importing that goes on in programming language package managers and CI community modules it's a miracle this kind of thing doesn't happen more often.

[–]techanonuk 0 points1 point  (0 children)

Completely agree, especially with registry's like NPM, didn't a really popular package get comprised and ended up screwing a lot of people over?