Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It’s foolish to feel safe because your package management solution hasn’t been attacked yet.

The attack vector is generalized.



It’s rational to feel much safer in the Java packages ecosystem, where pinned versions are the default and the norm, and packages cannot run any install-time scripts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: