Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
illusive4080
14 days ago
|
parent
|
context
|
favorite
| on:
Shai-Hulud malware attack: Tinycolor and over 40 N...
At this time should we just consider all of npm unsafe for installing new packages? Installing a single package could install hundreds of transient dependencies.
meindnoch
14 days ago
[–]
Yes. Also, no need for "at this time".
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: