logoalt Hacker News

slopinthebagtoday at 3:33 AM3 repliesview on HN

It's reasons like this why I refuse to download Node or use anything NPM. Thankfully other languages are better anyways.


Replies

hrmtst93837today at 5:43 AM

Skipping Node sounds nice. PyPI and RubyGems have had the same mess, and npm gets more headlines because it is huge and churns fast, so you see more fresh landmines and more people stepping on them. Unless you plan to audit every dep and pin versions yourself, you're mostly trading one supply chain mess for another, with a tiny bit of luck and a differnt logo.

show 1 reply
wetpawstoday at 3:40 AM

[dead]