pull down to refresh

How the heck does an experienced open source maintainer fall for a phishing attack?

It must have been a very sophisticated and convincing phishing attempt?!