3 ms·
Then shouldn’t the analyzers just be part of NPMs acceptance requirements?
by user3939382 4mo ago
Then shouldn’t the analyzers just be part of NPMs acceptance requirements?
- zwily 4mo agoThat’s my point. For whatever reason, npm isn’t doing it. All npm users adding a minimum package age is kind of like doing it as a collective, without npm’s help.
- _flux 4mo agoI think if they did it, then attackers would be able to iterate their attack against their own project, and once it passes the filters they could deploy for real. I guess it could work better if it was enabled for only actual attack vectors projects.