Hacker News new | ask | show | jobs
by lelanthran 280 days ago
>

NPM has bigger problems - no adults in the room! For example, they've been rejecting signed packages since 2014 or thereabouts?

Expect npm repos to be overflowing with AI-submitted crap that will lower the signal substantially due to not having any sort of identify via signing.