Hacker News
new
past
comments
ask
show
jobs
points
by
foldr
11 hours ago
|
comments
by
consp
7 hours ago
|
[-]
And yet npm install [package with 1000 recursieve dependencies] is not considered a supply chain risk at all to those security/compliance jarls.
Let alone having to check all licenses...
reply