governance: introduce a background check for Spoon integrators
Open
governance
- Dominant language
- Java
- Stars
- 2k
- Forks
- 392
- Avg merge
- 11h 24m
- Merged PRs (30d)
- 36
Description
Dear all,
Recently, there have been a number of software supply chain attacks. Basically, malicious persons push malicious code in open-source software:
Spoon is concerned by this problem, because if somebody pushes a backdoor in Spoon, she would have access to lots of source code, incl. proprietary code.
Consequently, integrators have the great responsibility to avoid backdoors. But what happens if integrators themselves are the attack vector?
To remediate to this problem, one solution is to introduce some kind of background check before giving the integrator role.
WDYT?
Contributor guide
Assessment
This issue has not been assessed yet.