Hacker News new | past | comments | ask | show | jobs | submit login

Or just ship local copies of your dependencies. It's not that hard.



... and all of _their_ dependencies. And read through them all to make sure that the local copy that you shipped didn't actually include a deliberately obfuscated exfiltration routine.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: