Hacker News new | ask | show | jobs
by davidpfarrell 266 days ago
Wow so couldn't said security co's establish their own registry that we could point to instead and packages would only get updated after they reviewed and approved them?

I mean I'd prolly be okay paying yearly fee for access to such a registry.

2 comments

IIUC chainguard is this, but only for python, java, and docker images so far. https://www.chainguard.dev/libraries
I think it would be a no brainer for npm to offer this but idk why they haven’t
Probably because they would expose themselves legally? Not sure what the current situation is exactly, but I assume it's "at your own risk".