|
|
|
|
|
by jmull
1867 days ago
|
|
> ...arguably less secure as it is downloading code from the internet... Don't essentially all the options involve code downloaded from the internet? And you have to trust the source that it isn't malware or too buggy or insecure? Are you making a case that the maintainers of this package aren't trustworthy? Or maybe the operators of npmjs.com? I'm just not understanding the claim this is less secure than various other options. |
|