Security concerns arise over the use of the Easyjson library, maintained by developers with ties to Russia's VK Group, in numerous open source projects. Although no malicious code has been found, the potential threat of subversion due to geopolitical affiliations poses questions for US public and private sectors. Organizations are encouraged to assess trust and security protocols in open source software, with attention on contributors from nations considered adversaries.
4 Comments
Sort: