Hacker News new | ask | show | jobs
by deepsun 1358 days ago
Well, if we're talking about security, their ban on NPM is a good thing, that's a huge supply chain risk.

If you don't have a budget for the vetted repositories, it means you don't have a budget for the project within the security requirements. You shouldn't be circumventing the security requirements, you should escalate the issue.

PS: of course I'm not talking about other things like MITM certs, that only reduces security.