Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
DecoySalamander
3 months ago
|
parent
|
context
|
favorite
| on:
NPM debug and chalk packages compromised
It really isn't, and I've never seen anyone do that. In every project I've worked on in the past decade, dependencies were only occasionally bumped in the context of some maintenance task or migration.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: