Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
woodruffw
on Nov 17, 2021
|
parent
|
context
|
favorite
| on:
Security issue related to the NPM registry
The longer term solution to this is public key signatures with an ephemeral key, rooted to some trusted identity source (e.g., a GitHub account with strong 2FA). There’s lots of work on that front coming out of the Open Source Security Foundation.
Join us for
AI Startup School
this June 16-17 in San Francisco!
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: