logoalt Hacker News

Rp8yXmdmrtoday at 2:12 PM1 replyview on HN

You are absolutely right. The dangerous part of NPM packages is the post-install script. Therefore moving from JavaScript to Java removes the threat.


Replies

grezqltoday at 2:16 PM

[dead]