Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.
Post
Remote status
Context
1> developers not working in an isolated environment (zone, vm, jail, etc) and letting their devtools access their whole laptop
they deserve it
Replies
9@feld @mhoye @sun@shitposter.world @mischievoustomato
I think we're talking past the point here - say you run your whole dev environment in a VM - sure, *your* OS is fine, but the packages you've trusted for years that you're including as dependencies have just been fucked, and that's what you're shipping to *me*, the end user.
Did I "deserve it"? I put it to you that I don't. I also don't think "everyone should just run everything in a container because someone wants to use some LLM agent in their gitforge" is the same as "don't install a random exe from a random warez site".
How did I deserve to have my box popped because you, a trustworthy dev, used a package that's trustworthy for years? This thinking makes no sense.