Comment on NPM Package With 56K Downloads Caught Stealing WhatsApp Messages

<- View Parent
wildbus8979@sh.itjust.works ⁨2⁩ ⁨days⁩ ago

I’m not super familiar with Maven so I could be wrong, but doesn’t Maven still pull depencies from upstream? That doesn’t fix the problem. Having depencies packaged in the OS means there is in theory some level of overview and review by the package maintainer(s).

source
Sort:hotnewtop