Hacker News new | ask | show | jobs
by bitmasher9 14 days ago
It’s foolish to feel safe because your package management solution hasn’t been attacked yet.

The attack vector is generalized.

1 comments

It’s rational to feel much safer in the Java packages ecosystem, where pinned versions are the default and the norm, and packages cannot run any install-time scripts.