Yup, the only way to combat this as a smalltime dev would be to turn off auto updates and make people build from source.
Why woul building from source be safer? Are you veting every single line of third-party source code you compile and use?
yea `curl <url> | gcc` is much safer...
Why woul building from source be safer? Are you veting every single line of third-party source code you compile and use?