• just_another_person@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    15 days ago

    They should have some sort of static code scanners on the repos at rest at this point that look for certain patterns and issue warnings.

    • Tetsuo@jlai.lu
      link
      fedilink
      English
      arrow-up
      1
      ·
      15 days ago

      I wish it was that simple but I doubt there is any scanner that can differentiate between legitimate and malicious code.

      Maybe an AI but even then it would probably be quite unreliable.