Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's why I use my distro's package manager and review external scripts before running them.


Same here. PyPI and NPM are the Wild West too. Github makes no effort to combat typosquatting either.

People in glasshouses shouldn’t throw stones...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: