TA-Lib / ta-lib

TA-Lib (Core C Library)
https://ta-lib.org/
BSD 3-Clause "New" or "Revised" License
602 stars 152 forks source link

Trust issues !!! #32

Closed summa-code closed 1 month ago

summa-code commented 7 months ago

With recent incident with XZ utils in Linux, how do we trust the contributing authors? Not questioning the authenticity of the original author. But not sure about the other contributors.

mario4tier commented 4 months ago

Thanks for your confidence, but you should not trust me neither :smile:

My Github account could be hijack etc...

A few relatively good news with TA-Lib:

Opinion

I think the bigger problem is NOT with open-source projects.

Guaranteeing a complete secure developer setup is hard. Example:

VSCode add-ins are blindly giving 100% access to the host... and many of these add-ins are closed source.

summa-code commented 1 month ago

I hear you. Thanks for the update.