|
|
|
|
|
by Someone1234
21 days ago
|
|
I suppose. But that's a "Perfect is the enemy of good"-like argument. Wherein: Why even reduce an easy to exploit attack surface when there could be holes elsewhere?! Because, you know, it makes things much more secure even if imperfect. Plus, to me, it is a culture issue. npm just doesn't take security seriously, so we don't see these improvements, and if there was additional test hardening later, I don't expect we'd see them in npm either. Since, they just don't care. |
|
Meanwhile in the nuget ecosystem is way smaller and have way less mainteners involved for a single given dependency.