Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not sure about NPM specifically, but in general: Pick a specific version and have your build system verify the known good checksum for that version. Give new packages at least 4 weeks before using them, and look at the git commits of the project, especially for lesser-known packages.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: