top | item 45214260

(no title)

blizdiddy | 5 months ago

And how many dependencies does Hono have? Looks like about 26. And how many dependencies do those have?

A single static zig executable isn’t the same as a a pipeline of package management dependencies susceptible to supply chain attacks and the worst bitrot we’ve had since the DOS era.

discuss

order

bakkoting|5 months ago

> And how many dependencies does Hono have?

Zero.

I'm guessing you're looking at the `devDependencies` in its package.json, but those are only used by the people building the project, not by people merely consuming it.

PxldLtd|5 months ago

That doesn't prevent supply chain attacks. Dev dependencies are still software dependencies and add a certain level of risk.