Hacker news

  • Top
  • New
  • Past
  • Ask
  • Show
  • Jobs

Show HN: DepsGuard – One command to harden NPM/pnpm/yarn/bun/uv configs (https://github.com)

40 points by eranation 4 days ago | 6 comments | View on ycombinator

jcjmcclean 3 days ago |

I love this! Although I've already gone through and made manual updates, I'll still give this a try. It's worth it even just to verify that I haven't missed anything. Thanks for sharing.

drcongo 4 days ago |

I tried this out after finding it on one of your comments yesterday, the good: it set some values in global config files for me which was handy, the not so good: I still haven't managed to make it find any project-level configs. Either way, it's a nice little tool, thanks.

craftedcode 4 days ago |

The "did it save someone from a supply chain attack? Also probably yes" line is great. The problem with security tooling is exactly this — you never see the attack you prevented.