Hacker Newsnew | past | comments | ask | show | jobs | submit | algoma's commentslogin

It would be possible to do this by querying the specs repo https://github.com/CocoaPods/cdn.cocoapods.org. This is what the web-app does.

I noticed that quite a few pods have more than 1 distinct source when checking the pods used by projects I have worked on. From what I could see source changes were the result of ownership changes, GitHub account name changes, etc.

So i'm not sure how to distinguish malicious source changes from innocuous ones. Maybe it would be worthwhile to search for source changes that lasted a single release and reverted thereafter.


Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: