Hacker News new | ask | show | jobs
by Joeri 39 days ago
Blaming the victim is too easy. NPM is unsafe at any speed. You cannot use it in any but the most trivial capacities without opening yourself up to supply chain attacks.

Why is npm the only package ecosystem that has so many problems? What are the other package system owners doing better? Let’s start there, instead of blaming the victims.

1 comments

This is talking about Linux packages. So no, not just npm.