Skip to content

Try to mitigate starjacking #3514

@oalders

Description

@oalders

https://security.metacpan.org/docs/cpan-starjacking.html

Right now we make no effort to assert that a repository is actually associated with the module which claims to live there or that the last releaser has write permissons on that repository.

So, you could, in theory, add a repository with a lot of GitHub stars to your module metadata, and MetaCPAN would display that number of stars for your module, making it appear potentially much more popular than it really is.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions