Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
Chyzwar
2mo ago
0 comments
Save
Share
This could be controlled by npm. Client ask for available versions anyway. If package is security fix then it can be made available instantly. But this delay gives time for security scanners and time to notify maintainers that package was published.
0 comments
1 comments · 1 top-level
top
newest
oldest
mcintyre1994
2mo ago
Then the malicious packages would always be published as a security fix.
j
/
k
navigate · click thread line to collapse