|
|
|
|
|
by marginalia_nu
681 days ago
|
|
We can empirically observe that NPM-sphere is relatively alone among software ecosystems to have this particular problem. This is an indication that the problem is either with some facet of NPM itself, javascript the language or js programmers, as that is what distinguishes the ecosystem from e.g. Maven or Pip that do not suffer from the same problems, at least not to the same extent. However, going from this observation to isolating causal factors is a lot harder, and randomly guessing isn't very likely to hit the mark. |
|
[1] claims that half of Python packages have security issues.
[2] says that the Rust supply chain has security issues.
just as two examples.
---
[1]: https://www.theregister.com/2021/07/28/python_pypi_security/
[2]: https://news.ycombinator.com/item?id=40864787