Re: Open source archives hosting malicious software packages
[email protected] (David Cantrell) Wed, 20 Sep 2017 15:33:53 +0100
| Newsgroups | perl.cpan.workers |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Sep 15, 2017 at 07:11:49PM -0400, James E Keenan wrote: > http://www.theregister.co.uk/2017/09/15/pretend_python_packages_prey_on_poor_typing/ > > Would CPAN be subject to the same problem as described in the article above? Yes. DBI::Class, for example, could be a typo for DBIx::Class or a misremembered Class::DBI, and there's nothing stopping anyone from uploading a DBI::Class package that does all kinds of dodgy stuff. -- David Cantrell | semi-evolved ape-thing Longum iter est per praecepta, breve et efficax per exempla.