←back to thread

1208 points jamesberthoty | 1 comments | | HN request time: 0s | source
Show context
illusive4080 ◴[] No.45267045[source]
At this time should we just consider all of npm unsafe for installing new packages? Installing a single package could install hundreds of transient dependencies.
replies(1): >>45267401 #
1. meindnoch ◴[] No.45267401[source]
Yes. Also, no need for "at this time".