Hacker News new | ask | show | jobs
by madarco 25 days ago
meanwhile pnpm 10.x by default won't donwload packages younger than a day
2 comments

Is one day enough to find vulnerabilities? Who keeps an eye on new releases? Otherwise the problem continues to exist, just delayed by one day.
There’s almost a dozen cybersecurity companies scanning NPM publishes in real-time and analysing them.
*11.x