Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

better overview on the main release blog: https://github.blog/2023-04-19-introducing-npm-package-prove...


Yes, and second analysis by an independent party: https://socket.dev/blog/npm-provenance




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: