Yeah it's a dumpster fire, but I also don't think the other major ecosystems like say python's pypi are any safer structurally
Yeah it's a dumpster fire, but I also don't think the other major ecosystems like say python's pypi are any safer structurally
There are npm supply chain exploits in the news every other day. I'm honestly surprised that something as decentralized as Go Modules is more reliable, but here we are. The fact that we're not seeing these stories about e.g. Maven is not at all surprising, given the limited need for third party libraries and the culture of careful upgrades in the Java ecosystem. If npm proponents want the ecosystem to survive, they need to demand / create better and stop making excuses.