Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
ptx
26 days ago
|
parent
|
context
|
favorite
| on:
Shai-Hulud malware attack: Tinycolor and over 40 N...
NPM lock files seem to include hashes for integrity checking, so as long as you check the lock file into the VCS, what's the difference?
cxr
26 days ago
[–]
Wrong question; NPM isn't bedrock. The question to be answered if there is no difference is, "In that case, why bother with NPM?"
Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: