3 ms·
Vetting the author of the package is neither very realistic in a lot of cases, nor a great solution to this problem unfortunately. A lot of people got impacted
by bloodyvalentine 5y ago
Vetting the author of the package is neither very realistic in a lot of cases, nor a great solution to this problem unfortunately. A lot of people got impacted by this issue through Karma, which is extremely popular and trusted by the community. In this case, the bad actor also managed to access ua-parser-js author's NPM account and push the bad version directly, so not really the case of an author going rogue.