Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Granted it wouldn't save those adding a new package to a project the first time

Right, that's the real problem.



independent site that maps packages to author certs that npm uses for verification at install time?

also, this is a problem that every package mgmt system faces. they alert on changes on upgrade but there's a requirement at the end user level to verify that at install time, the cert being trusted is the right one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: