Hacker News new | ask | show | jobs
by cjalmeida 536 days ago
You’d be surprised by the amount of companies handling critical infrastructure that are OK with using PyPI directly
3 comments

He said companies that care, not companies that should care but do not.
really depends on the company. my company cares a lot about security because it's a huge fortune 50 company with sensitive data and a lot of reputation could be lost with a security scandal
That is somewhat terrifying