Hacker News new | ask | show | jobs
by the42thdoctor 1554 days ago
> Honest question, what can be done to address this type of issue?

Paid subscription-based NPM ? Yes, you could download a dependency directly from the repository on Github for free, but if do so through the paid NPM they assure you that the package is malware-free.