Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there a way to detect/filter dependencies that use HTTP URLs as dependency specifiers as part of an NPM install? Since you can send specific requesters different payloads, I can see how this would bypass most of the normal scanning tools.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: