Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
pas
4 months ago
|
parent
|
context
|
favorite
| on:
Post Mortem: axios NPM supply chain compromise
code becomes trusted by review, but these crowd sourcing efforts to do so fizzled out, so in practice we have weak proxies like number of downloads
the implicit trust we have in maintainers is easily faked as we see
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
the implicit trust we have in maintainers is easily faked as we see