I was surprised to see that Gnome 3 extensions are updated automatically by Debian. Hence, I am wondering:
Which community procedures or practices make it difficult to inject harmful code in this way?
Which community procedures or practices make it difficult to inject harmful code in this way?
There's a human review process, https://gjs.guide/extensions/review-guidelines/review-guidelines.html#basics