Re: Popular Python Package 'ctx' Hijacked to Steal AWS Keys

May 25, 2022
3:04 p.m.
Turritopsis Dohrnii Teo En Ming <tdtemccna@gmail.com> ezt írta (időpont: 2022. máj. 25., Sze, 15:49):
Hi All, it's got to my mind that PYPA, community, and developers should develop some mechanism to protect against similar threats. For example security checkers could be added to the upload flow, before a package appears, and becomes downloadable. Compiled parts should be allowed only in source, and security checkers would check those too, and compile from source and publish package only after these checks executed and did not found any harmful thing. BR, George
1029
Age (days ago)
1029
Last active (days ago)
0 comments
1 participants
participants (1)
-
George Fischhof