Hacker News new | ask | show | jobs
by ncphillips 2872 days ago
Wouldn’t this be the case for any node app? Why pick on VuePress specifically?
1 comments

The OP's comment was specifically with respect to the large number of dependencies, which can increase the "surface area" for this type of attack to happen. And, of course, we're talking about VuePress because this is a thread about VuePress. Similar complains are raised for many other Node libraries, so rest assured that VuePress is not alone in that regard.