|
|
|
|
|
by CaptainOfCoit
275 days ago
|
|
> That's exactly npm's problem, though. I don't think that's the problem with npm. The problem with npm is that no packages are signed, at all, so it ends up trivial for hackers to push new package versions, which they obviously shouldn't be able to do. |
|
That is, how does signing prevent publishing of malware, exactly?