Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
nabogh
3 months ago
|
parent
|
context
|
favorite
| on:
Postmortem: TanStack NPM supply-chain compromise
Some sort of middle ground should have been found where the unpublished package is still accessible as an archive or something. I'd much rather get my package broken than get hacked
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: