Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> That seems a bit excessive to sandbox a command that

> really just downloads arbitrary code you are going to

> execute immediately afterwards anyways?

I don't want to stereotype, but this logic is exactly why javascript supply chain is in the mess its in.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: