Hacker News new | ask | show | jobs
Safe Chain prevents developers from installing malware (npmjs.com)
11 points by danfritz 269 days ago
1 comments

I think it’s a valiant effort, but misses the forest for the trees.

It’s another dependency - which comes with 6 more dependencies. One of which is ‘Chalk’, which was one of the recently malware-infected packages. Unless it’s a joke, and the Chalk dependency is just the punchline.