logoalt Hacker News

slowin • yesterday at 6:48 PM • 1 reply • view on HN

It's not just the complexity. You're also vulnerable to supply chain attacks via NPM. It's also performance as you don't need the entire javascript runtime just for a CLI.


Replies

isopede • yesterday at 8:20 PM

Pretty much every modern language with a package repository is vulnerable to supply chain attacks.

Are there any languages doing something unique or are especially resilient in this respect?

➕ show 1 reply