logoalt Hacker News

iconicBarktoday at 2:41 PM2 repliesview on HN

Is this more secure?? I would genuinely love to know


Replies

n_etoday at 3:00 PM

Yes (assuming they're doing frontend dev and including the resources from the page). The code is fetched and executed from the browser, so It'll have to escape the browser sandbox to do something nefarious.

bdcravenstoday at 2:47 PM

Yes, none of npm's lifecycle hooks. You're just pulling bytes over the wire.

show 1 reply