• can@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 days ago

    The only way to mitigate this risk is to verify package names manually and never assume a package mentioned in an AI-generated code snippet is real or safe.

    We’re doomed