Hacker News new | ask | show | jobs
by ajross 17 days ago
PyPI and Cargo are, 100%, vulnerable to this same class of compromises. That NPM sucks isn't a statement that everyone else doesn't.