Hacker News new | ask | show | jobs
by kachapopopow 259 days ago
the chance the dependency you've just updated and your vault being unlocked at the same exact time, if someone is attacked by a malicious dependency you have bigger problems to worry about.