Hacker News new | ask | show | jobs
by algesten 2899 days ago
This seems like a good idea. If a package has more than x downloads or y dependencies, then require 2fa for publishing it.