• magic_lobster_party@fedia.io
    link
    fedilink
    arrow-up
    28
    ·
    12 hours ago

    it’s the kind of dependency developers install without a second thought

    I got a feeling this is an attack vector that will continue to grow, as now there’s vibe coding frameworks installing random dependencies without a thought at all.

    • corsicanguppy@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      ·
      10 hours ago

      There’s twonthings at play, here:

      • installing dependencies without checking
      • a framework that will allow this

      Both are absolutely the fault of the user.