Package registries

Publishing to a public registry means claiming a name. It does not mean anybody checked anything.

There is no vetting of what the package does, and the name is not evidence of authorship or quality. This is not a flaw in the registries so much as a widely held misunderstanding of what they are: distribution infrastructure, not a review body.

Checked against the primary source.

More on Software supply chain & DevSecOps