Hacker News new | ask | show | jobs
by phendrenad2 1105 days ago
The same could be said about NPM, or pip, or crates. The security model is "they will probably find the backdoor before it affects me", and it's unreasonably effective.