| ▲ | montroser 4 hours ago | |||||||
I agree with much of what you said here, but is it really just about the package manager? If I had specified this repo's git url with a specific version number or sha directly in my package.json, the outcome would be just about the same. And so that's not really an end-run around version control at that point. Even with npm out of the picture the problem is still there. | ||||||||
| ▲ | Gigachad 3 hours ago | parent [-] | |||||||
The root problem is the OS allows npm packages to grab your WhatsApp messages without the user knowing. | ||||||||
| ||||||||