logoalt Hacker News

dec0dedab0deyesterday at 6:26 PM1 replyview on HN

The project authors probably don't even know what libraries their project requires, because many of them are transitive dependencies. There is zero chance that they have checked those libraries for supply chain attacks.

This is the best reason for letting users install from npm directly instead of bundling dependencies with the project.


Replies

bluGillyesterday at 6:32 PM

What user is going to check dependencies like that?

show 2 replies