Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
shadowgovt
on Jan 10, 2022
|
parent
|
context
|
favorite
| on:
Dev corrupts NPM libs 'colors' and 'faker', breaki...
This can be resolved by just pinning version in npm, right? I mean, it's a malicious attack that compromises trust in the maintainer of the package, but it's not the end of the world for any team being conscientious of their dependencies.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: