Comment on Investigating a backdoored PyPI package targeting FastAPI applicationsparentComments−Alex39173yYour threat model now must include the GitHub account of every maintainer of every open source project you use.But GitHub is afaik the only site on the Internet that actually does account management correctly, so it least there is that.
Comments
But GitHub is afaik the only site on the Internet that actually does account management correctly, so it least there is that.