1
Ask HN: What are some solutions for ensuring package security?
In light of _another_ NPM worm, I am wondering what can new languages do to avoid such problems. I recall reading somewhere about auditable software supply chains?
Currently, I’m using csrankings as a signal, but I’m aware that those are based on research outputs, so it may not correlate with teaching quality. Or does it?
What do you think?
Thanks!