logoalt Hacker News

Havocyesterday at 9:59 PM1 replyview on HN

Yeah it's a dumpster fire, but I also don't think the other major ecosystems like say python's pypi are any safer structurally


Replies

gredyesterday at 10:51 PM

There are npm supply chain exploits in the news every other day. I'm honestly surprised that something as decentralized as Go Modules is more reliable, but here we are. The fact that we're not seeing these stories about e.g. Maven is not at all surprising, given the limited need for third party libraries and the culture of careful upgrades in the Java ecosystem. If npm proponents want the ecosystem to survive, they need to demand / create better and stop making excuses.