Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Or, npm can add trust ratings to packages and versions. And Github the parent company can lend a tiny fraction of resources and programmer power to developing static code analysis tools for npm packages.

    This problem is completely solvable in two different ways:

    1) everyone uses private feeds that use vetted versions only, and

    2) Github/npm take responsibility for every package published to npm as the distributor.

    Also the name Shai-hulud was chosen by the people who made the malware, you shouldn't dignify them by using the name they chose.

Explore Birbla archives