logoalt Hacker News

general_revealtoday at 1:50 PM4 repliesview on HN

That’s why I switched to Java.


Replies

Rp8yXmdmrtoday at 2:12 PM

You are absolutely right. The dangerous part of NPM packages is the post-install script. Therefore moving from JavaScript to Java removes the threat.

show 1 reply
keyletoday at 1:57 PM

    AbstractFinalFactoryShaiHuludSerialisedFactory
show 2 replies
UqWBcuFx6NV4rtoday at 1:55 PM

…. lol

mschuster91today at 2:36 PM

Meh maven plugins are just as juicy a target as npm is

show 2 replies