Hacker News
new
past
comments
ask
show
jobs
points
by
jorams
4 hours ago
|
comments
by
Slothrop99
2 hours ago
|
next
[-]
Obviously way too easy to take over these 'orphaned' packages if it can be done in an automated manner. GitHub/NPM/etc doesn't have this issue, they need to stop equivicating. Sounds more like an anonymous FTP site.
reply
by
mrbluecoat
1 hours ago
|
prev
|
[-]
This.
Who needs social engineering NPM maintainers when there are thousands of freebie AUR ones.
reply