logoalt Hacker News

zymhanyesterday at 5:57 PM1 replyview on HN

Installing 3rd party packages the way Node and Python devs do regularly _is_ a security hole.


Replies

fn-moteyesterday at 6:06 PM

We definitely agree on that. Fortunately some of the 600+ comments here include suggestions of what to do about it.