Comment by mapontosevenths
4 days ago
This is how everyone does it now. Including Anthropic.
To be fair, is that any different from naively trusting NPM? It's not like NPM is doing any vetting. They're every threat actors favorite sandbox these days.
No comments yet
Contribute on Hacker News ↗