Comment by replete Comment by replete 13 hours ago 0 replies Copy Link View on Hacker News A whitelist in package.json is only a partial assist