Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If an attacker rug-pulls of course there is nothing that can be done about that other than security scanning.

As another subthread mentioned (https://news.ycombinator.com/item?id=45261303), there is something which can be done: auditing of new packages or versions, by a third party, before they're used. Even doing a simple diff between the previous version and the current version before running anything within the package would already help.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: