Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
tcoff91
7 months ago
|
parent
|
context
|
favorite
| on:
Oh no, not again a meditation on NPM supply chain ...
It seems to me like one obvious improvement is for npm to require 2fa to submit packages. The fact that malware can just automatically publish packages without a human having to go through an MFA step is crazy.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: