kuijsten
honked back 23 Dec 2025 11:00 +0100
in reply to: https://cybervillains.com/users/djm/statuses/111255948769148166
@damienmiller could you elaborate a bit on how manifest v3 can mitigate supply chain attacks? There's nothing that can stop a hijacked developer account pushing a new malicious update, is there? As stated here: https://cybervillains.com/@djm/111255948769148166 in this (old) thread https://infosec.exchange/@lcamtuf/111253626757075766