-
Notifications
You must be signed in to change notification settings - Fork 32
Open
Labels
enhancementNew feature or requestNew feature or request
Description
I think packages should only be pushable to the registry by proven maintainers. For example my library forge-gas-snapshot is in the registry, but not published by me and I'm unable to update it. I'm a bit concerned about supply chain issues where malicious versions of packages can be published at known but unclaimed names
Given github repository names are the current standard for package management, One way to avoid this issue is to authenticate with github to claim the name of an existing solidity package
johnsaigle and PaulRBerg
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request