Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
thedougd
8 months ago
|
parent
|
context
|
favorite
| on:
NPM debug and chalk packages compromised
It was a pain in the ass but I always appreciated that Maven central required packages to be signed with a public key pre-associated with the package name.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: