Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
erik_seaberg
on July 12, 2018
|
parent
|
context
|
favorite
| on:
ESLint compromised, may have stolen your credentia...
RPM and .deb packages have GPG signatures and lists of trusted maintainers. NPM doesn't have that;
https://medium.com/redpoint/introducing-pkgsign-package-sign...
looks like a very early start on a big project that could fix this if it catches on.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: