Hacker News new | past | comments | ask | show | jobs | submit login

yep.

same with npm. i publish releases of my OSS libs to npm, but there's no guarantee that what is uploaded is what you see on github. that's a lot of trust you have to put into my opsec, etc. not good.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: