Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
JodieBenitez
4 months ago
|
parent
|
context
|
favorite
| on:
Shai-Hulud Returns: Over 300 NPM Packages Infected
I don't know if it's a common or even a good practice, but I like to go mod vendor and add the result to my repo.
bpavuk
4 months ago
[–]
I do `cargo vendor` sometimes, but that's mostly to enable offline work and use the debugger inside some vague crates (Rust's libraries-but-not-really), and usually I gitignore the `vendor`'ed crates away.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: