Hacker News new | ask | show | jobs
by leftshift 1795 days ago
It depends, attacks via build pipelines can be devastating.
1 comments

Yep.

Unfortunately it’s not clear cut that we don’t have to worry about devDependencies vulnerabilities.