Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do we need a “days since last NPM-related security disaster” tracker?


Can someone instead, make a utility that assuming that my project's packages only get upgraded, not downgraded, could have been compromised or included compromised code? We could then check on each of our projects. If you do downgrade packages then you'd have to run it on prior commits as well.


Someone should make this!


For what purpose other than feeling smug?


To shame the community into doing something, maybe.


Would you shame a child for making a mistake? Shame should be reserved for malice and nefarious action with intent.


Got it, so we should treat the npm community as a child, right?


I would shame an adult who keeps making mistakes that are massively impactful on many others. Given npm's scope within the tech world, there's no way they can be fairly described as a "child". They're a hugely significant entity, and need to act like it.


It's not just shaming for a mistake - it's shaming for repeatedly making mistakes because they're too lazy to implement a mistake-preventing solution.


Yeah, I would shame a child for a repeated reckless mistake.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: