replacing removed projects in dub

James Blachly james.blachly at gmail.com
Fri Mar 12 13:46:54 UTC 2021


On 3/11/21 5:17 PM, Steven Schveighoffer wrote:

> Should it be possible to "take over" a project in dub once the 
> maintainer has deleted all their stuff? I have a copy of the repo 
> (thanks to WebFreak), so I could do it, but I wonder if dub shouldn't 
> have a way to mitigate this type of problem.

Unequivocally no. Replacing new code into the same namespace as an 
existing/established package is a major potential malware vector.


More information about the Digitalmars-d mailing list