logoalt Hacker News

MetaWhirledPeasyesterday at 9:01 PM3 repliesview on HN

Other package managers are magically immune?


Replies

c2h5ohyesterday at 9:06 PM

They are not, but npm is uniquely bad in that regard. Refusal to implement security features that would have made attacks like this harder really doesn't help https://github.com/node-forward/discussions/issues/29

show 1 reply
mayamatoday at 1:26 AM

You could write most of the cli tools using stdlib in python and go, without need for including hundreds of libraries even for trivial things.

NamlchakKhandrotoday at 4:26 AM

yes obviously.

isn't it obvious?

it should be obvious.

why isn't obvious?