Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
rs186
23 days ago
|
parent
|
context
|
favorite
| on:
Oh no, not again a meditation on NPM supply chain ...
When your only dependencies are Spring and Apache Commons, which requires legal approval in your corporation to use, and each update requires scrutiny, it's hard to get any supply chain attacks, right?
Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: