logoalt Hacker News

lelanthrantoday at 9:19 AM0 repliesview on HN

Because that's precisely what is needed: an easy way to ship dependency malware like npn, pip, cargo, etc.

Like it or not, having a little bit of friction prevents pulling in packages with thousands of transitive dependencies.