Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't know much about node but cargo has lock file with hashes which prevents dep substitution unless dev decide to update lock file. Updating lock file has same risks as initial decision to depend on deps.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: