Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Safe Chain prevents developers from installing malware (npmjs.com)
11 points by danfritz 9 days ago | hide | past | favorite | 1 comment




I think it’s a valiant effort, but misses the forest for the trees.

It’s another dependency - which comes with 6 more dependencies. One of which is ‘Chalk’, which was one of the recently malware-infected packages. Unless it’s a joke, and the Chalk dependency is just the punchline.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: