Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Reproducible builds, sure. Security? that's a different story.

https://github.com/ChALkeR/notes/blob/master/Gathering-weak-...

- node ships with npm

- npm has a high number of dependencies

- npm does not implement good practices around authentication.

Can someone compromise npm itself? probably, according to that article.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: