logoalt Hacker News

gear54rustoday at 3:39 PM1 replyview on HN

The above comment is just a bunch of generalizations not meant to address seriously that's why.


Replies

rvztoday at 3:48 PM

So the comparison here is that you would rather trust a password manager with a CLI that imports hundreds of third-party dependencies over a first party password manager with a CLI that comes with the OS?

I don't think macOS Keychain uses NPM and it isn't in TypeScript or Javascript and, yes it does not need a CLI either.

The NPM and Java/Typescript ecosystem is part of the problem that encourages developers to import hundreds of third-party libraries, due to its weak standard library which it takes at least ONE transitive dependency to be compromised and it is game over.

show 2 replies