3 ms·
> And if we are concerned, we should, he would advise, simply make a fork and write an email to npm to warn them. Well... yeah. If you don't trust him, don't t
by gregknicholson 8y ago
> And if we are concerned, we should, he would advise, simply make a fork and write an email to npm to warn them.
Well... yeah. If you don't trust him, don't trust him.
If you don't trust NPM's vetting, don't trust NPM's vetting.
- mattdeboard 8y agonpm does vetting?
- cmorgan31 8y agoNPM increased their efforts with regards to auditing. They realized it was a prominent attack vector and without them taking responsibility for some level of the problem they would be throwing their reputation down the drain. It isn't perfect, but it's a step to improving the situation.
- mattdeboard 8y agoSweet! There are so many brilliant & creative people in the Node community. I'm positive there are some innovative ways to approach this problem.