Hacker News new | ask | show | jobs
by silverwind 269 days ago
save-exact is mostly useless against such attacks because it only works on direct dependencies.
1 comments

Why, though?