Skip to content

Add warning / Improve security around installing ethpm URIs #94

Description

@njgheorghita

Only install packages from registries you trust is a major requirement of ethpm. You should always trust the owner of a registry before installing (or activating) a package.

It might be a good idea to implement some kind of loose confirmation when you want to install / activate a package....

> ethpm install ethpm://0x123abc/wallet@1.0.0
Installing a package from the registry @ 0x123abc.
The owner of this registry is: 0x456def.
Do you  trust this owner? Are you sure you want to install packages from their registry?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions