Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
andrewmcwatters
on Jan 10, 2022
|
parent
|
context
|
favorite
| on:
What NPM should do to stop a new colors attack
Easy, make --save-exact default behavior. We don't have stable subresource integrity in Node.js yet, but this would be the next best thing.
Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: