Hacker News new | ask | show | jobs
by bakugo 1311 days ago
Millions of developers run random javascript on their computers on a daily basis. It's called npm. How is this any less trustworthy?
1 comments

It isn't, but those millions of developers are why software supply chain security is a topic now (and why it causes me no ends of headaches, even though I do C++!).