Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

slowly walking through a minefield isn’t any safer than running.

So unless you’re saying the extra time will be spent inspecting every package, whenever you do update, you will be getting an insecure package.

You’re not safe by dodging axios. There are currently thousands of breached packages ready to install that aren’t notable.

“I’ll run npm install after checking twitter” won’t help



Most packages don't become unsafe just because they were released a week ago.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: