<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: packattest</title><link>https://news.ycombinator.com/user?id=packattest</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 06 Apr 2026 02:07:14 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=packattest" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by packattest in "Preventing accidental NPM leaks by reviewing the final artifact"]]></title><description><![CDATA[
<p>One thing I’m curious about:<p>We’ve focused a lot on provenance (where artifacts come from), but less on verifying what actually gets published.<p>Feels like both are needed — provenance + explicit artifact review.<p>Curious if others have seen similar issues in other ecosystems (pip, cargo, etc).</p>
]]></description><pubDate>Sun, 05 Apr 2026 14:34:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47649885</link><dc:creator>packattest</dc:creator><comments>https://news.ycombinator.com/item?id=47649885</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47649885</guid></item><item><title><![CDATA[Preventing accidental NPM leaks by reviewing the final artifact]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/divohna/PackAttest">https://github.com/divohna/PackAttest</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47649478">https://news.ycombinator.com/item?id=47649478</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Sun, 05 Apr 2026 13:53:55 +0000</pubDate><link>https://github.com/divohna/PackAttest</link><dc:creator>packattest</dc:creator><comments>https://news.ycombinator.com/item?id=47649478</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47649478</guid></item></channel></rss>