Hacker News new | ask | show | jobs
by subway 3677 days ago
Because thousands of people place their trust poorly.
1 comments

Do you have any specific complaints with npm?
Reliance on transport security instead of providing cryptographic verification of code is my biggest beef, very closely followed by what is essentially a nonexistent reputation system (or, in lieu of a code reputation system, a curated selection of packages).