3 ms·
The baffling part is why it takes hours for the npm security team to unpublish packages that contain malware, as attested by multiple independent sources? That
by igregoryca 5mo ago
The baffling part is why it takes hours for the npm security team to unpublish packages that contain malware, as attested by multiple independent sources? That should be able to happen in minutes.
- consumer451 5mo agoWho vets the sources, and using what scheme?
- tomjen3 5mo agoIf email matches owner of repo, pull now. If not verified, ban and restore later.
- linkregister 5mo agoIt would take longer than minutes to validate the claims themselves.