logoalt Hacker News

raesene9today at 3:24 PM0 repliesview on HN

not really, there are a number of security companies doing analysis of any new packages looking for supply chain attacks, so if you wait a couple of days, till their analysis is complete, you're reducing the risk of hitting a compromised package.