←back to thread

441 points longcat | 1 comments | | HN request time: 0.204s | source
Show context
neya ◴[] No.45043071[source]
Just a normal day in Javascript land.

laughs in elixir

replies(1): >>45051129 #
1. christophilus ◴[] No.45051129[source]
It’s not like Hex has some magical way of only downloading non-malicious packages.

If Hex gets popular enough, it will happen there, too. Even if the install process doesn’t run arbitrary code, when you actually load the library, it can do stuff, so I don’t see any reason to gloat.