Hacker News new | ask | show | jobs
by davedx 343 days ago
If you download it first, you can at least eyeball what's been downloaded to check it doesn't start by installing a bitcoin miner
1 comments

How often do people do that when they install a package from npm, pypi, or other package repository? In practice never.