Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> It doesn't just download random things.

That's exactly what it does. The developer is not really expected to thoroughly review the codebase of every dependency.

Just like javascript, all sort of supply chain attacks are made possible.

A single malicious library can sneak into large ecosystems easily.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: