top | item 39881024

(no title)

snazz | 1 year ago

It’s similarly problematic but on a somewhat smaller scale and with fewer levels of nested dependencies.

discuss

order

eacapeisfutuile|1 year ago

I’m not sure this would be smaller scale? At least probably too early to tell?

snazz|1 year ago

I just mean fewer total packages and fewer maintainers. Linux libraries and packages don’t have the culture of making a package out of a single small function and importing it everywhere, which is part of the reason why NPM is a good case study in opportunities for supply chain attacks.