logoalt Hacker News

igregorycatoday at 2:06 AM2 repliesview on HN

The baffling part is why it takes hours for the npm security team to unpublish packages that contain malware, as attested by multiple independent sources? That should be able to happen in minutes.


Replies

linkregistertoday at 3:20 AM

It would take longer than minutes to validate the claims themselves.

consumer451today at 2:27 AM

Who vets the sources, and using what scheme?

show 1 reply