Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While it's true that the packages are first party, .NET still relies on packages to distribute code that's not directly inside the framework. You still probably transiently depend on `Microsoft.Extensions.Hosting.Abstractions ` for example - if the process for publishing this package was compromised, you'd still get owned.
 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: