Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I like this pip metaphor. If we had required `--trust-remote-code` for every `npm install` we could have avoided left-pad and most of the software supply chain drama in the past years.


How would that have avoided left-pad? Do you just mean that people would have been discouraged from pulling in so many dependencies?


I think that would just teach people to type --trust-remote-code fast.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: