←back to thread

1208 points jamesberthoty | 2 comments | | HN request time: 0.424s | source
1. illusive4080 ◴[] No.45267045[source]
At this time should we just consider all of npm unsafe for installing new packages? Installing a single package could install hundreds of transient dependencies.
replies(1): >>45267401 #
2. meindnoch ◴[] No.45267401[source]
Yes. Also, no need for "at this time".