logoalt Hacker News

mschuster91today at 7:30 AM1 replyview on HN

> or only allowing widely used, well-maintained Javascript libraries.

That isn't a guarantee either, just last month someone compromised the Axios library.


Replies

skydhashtoday at 9:40 AM

They stole the axios's npm keys and they uploaded malicious artifacts. They did not takeover the axios's repo. The issue is with packaging and distribution, not with code.

show 1 reply