---
date: 2025-01-15T12:48:05+00:00
modified: 2025-01-15T12:48:05+00:00
permalink: https://kaspars.net/note/mastodon-social-113832918058619681
post_type: note
author:
  name: Kaspars
  avatar: https://reverse.kaspars.net/gravatar/avatar/92bfcd3a8c3a21a033a6484d32c25a40b113ec6891f674336081513d5c98ef76?s=96&d=mm&r=g
---

# On January 15, 2025 at 14:48

I just realized that with distributed WordPress packages and signing, all vendor code must be isolated to avoid one trusted vendor from publishing an update with another vendor's package content which would overwrite it.