Hacker News new | past | comments | ask | show | jobs | submit login

Using socket.dev is one way!

As for writing such a check manually, you would just need to check "bin" in */package.json after installing everything, and verify each script.

Trusting a big company seems to be another suggestion I see in this thread too. I don't agree with that one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: