this post was submitted on 23 May 2024
94 points (98.0% liked)
Programming
17398 readers
140 users here now
Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!
Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.
Hope you enjoy the instance!
Rules
Rules
- Follow the programming.dev instance rules
- Keep content related to programming in some way
- If you're posting long videos try to add in some form of tldr for those who don't want to watch videos
Wormhole
Follow the wormhole through a path of communities !webdev@programming.dev
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I look at the contributors on Github and check them out. I'll check out what else they've worked on and maybe see if they have an account on mastodon or twitter. Maybe I'll ask some friends if they've used or heard of the product, or know of the devs.
There is indeed malware disguised as OSS and you do sometimes have to vet them. I'll skim the codebase and see if there's anything that looks weird or funky, but that's not perfect (like in the case of the xz) and some stuff can slip by.