Another thing that they do that should make the process less vulnerable is they try to get developers involved in packaging their own applications (and have a verified badge, though I'm not sure how rigorous their verification is).
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
