Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
pcwalton
on Aug 2, 2017
|
parent
|
context
|
favorite
| on:
Malicious crossenv package on npm
You could still typosquat as e.g. @guyy/cross-env.
um_ya
on Aug 2, 2017
[–]
You would have to maintain that all package names are unique. The "cross-env" part would have to still be unique.
unkown-unknowns
on Aug 2, 2017
|
parent
[–]
No that's not good. Do scope but don't make package names unique.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: