Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Adding a hardcoded flag is not the same as asking the user if they want potential malware. If CI/CD is broken they should revert the change to pinned dependencies instead of trying to install a bleeding edge version of a new dependency that hasn't been scanned yet.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: