Hacker News new | ask | show | jobs
by mythz 2494 days ago
The issue with leftpad was that it was a transitive dependency that was yanked and broke everyone depending on it. Gists don't have any dependencies, their encapsulated within the Gist where all code is easily inspectable and publicly verifiable, maintained by a verified GitHub User and all changes have a public audit trail.

Yes the sandbox is the difference between Desktop Apps and Web Apps, which is the point, Desktop Apps can do things Web Apps can't do and when you're running a Desktop App you're trusting the publisher just like you are with every other process running on your System.