Am I the only one who thinks the way plugins are updated in lazy.nvim (and probably others) is a bit insane? It seems to just pull the latest commits. Every time I update, I feel one rogue commit away from someone stealing my keys. It definitely feels like the riskiest thing I do on my system. Or have I misunderstood something?
behnamoh|5 months ago
For me, lazy.nvim doesn't pull the latest commits automatically. I have to <leader>-L and SHIFT-U it. And I don't do it often exactly because if there's an issue with the plugins I hope it's caught by others and addressed before I update mine.
sim7c00|5 months ago
the nr of times now people have been owned by rogue plugins via editors is rising each day...
gitaarik|5 months ago
bayesianbot|5 months ago
recursivecaveat|5 months ago
freedomben|5 months ago
unknown|5 months ago
[deleted]