Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
nottorp
17 days ago
|
parent
|
context
|
favorite
| on:
GitLab discovers widespread NPM supply chain attac...
Or it's worse, because there's a good bunch of devs that don't trust MS by default?
AmbroseBierce
17 days ago
[–]
Even the most hardcore GNU supporters don't think Microsoft would add a supply chain attack to such initiative, or that their software security is worse than the average NPM (popular) package maintainer.
nottorp
16 days ago
|
parent
[–]
Just the lock in and telemetry are dangerous :)
And they're company policy as opposed to honest mistakes like security vulns.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: