Skip to content

Aube – Node.js package manager in Rust

aube.en.dev
14 pointsbrianzelip5 comments
On HN

Comments

Interesting has a 24hr cooldown before trusting package updates and a no-trust option for trusting downgrades given all the npm hacks and issues lately, smart move. I wonder if there's better ways to protect against this.

Same here; I hope the vulnerability discovery process evolves from "letting somebody else find out first". There are tons of vendors that scan the ecosystem, but I'd love something that works automatically at the point of install

appears vibecoded which doesn't give me confidence, still interesting though.

pnpm has also moved a few of its components from javascript to rust in its latest release

appears vibecoded

??

It's from the author of mise, https://mise.en.dev/.

Interesting, but it's still vibe coded.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.