4 ms·
What's not to like? The fact that every one of those dependencies is an attack vector when one of those package's maintainers gets compromised / project hijacke
by ts330 11y ago
What's not to like? The fact that every one of those dependencies is an attack vector when one of those package's maintainers gets compromised / project hijacked / bought off by some black hat operator.
It's easier to keep an eye on a small number of trusted parties than 200 random strangers.
You thought this SNAFU was bad...
- patates 11y agoThat has nothing to do with how granular packages are. The npm is broken as it allows such things. Look at this spectacular example of providing high security for users: https://www.npmjs.com/package/kik https://www.npmjs.com/package/kik Someone has to do this manually?! If the package is not popular, no one cares? What happens if I send them an email and provide the same package with the same API (not trademarked and MIT licensed) but break it a bit on every update? No one knows.
- ts330 11y agowhen those packages are not under your control, it has everything to do with how granular they are and by extension how many you depend on and thus have to trust/verify. when was the last time you rechecked the entire source of a package you depend on after updating it?