The v2 Forum
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Extensionstore -

| Risk | Mitigation | |------|-------------| | Malware in published extension | Reproducible builds + automated scanning (ClamAV, yara rules) | | Update poisoning | Code signing + certificate pinning | | Typosquatting | Name squatting checks + verified publisher badges | | Abandoned extensions takeover | Web of trust + expiration of signing keys |