logoalt Hacker News

matheusmoreiratoday at 10:24 AM1 replyview on HN

Every programming language package manager is affected. Any random person can sign up and push packages. They are all equivalent to the Arch Linux User Repository and have the exact same caveats.


Replies

grey-areatoday at 12:46 PM

I last added a new dependency to a large project I work on a couple of years ago. So no, not all ecosystems are the same.

The culture makes a difference.