7 ms·
> Consider the destructiveness of someone malicious befriending the left-pad developer, taking the project over, and doing a malicious push. Not different from
by Sacho 9y ago
> Consider the destructiveness of someone malicious befriending the left-pad developer, taking the project over, and doing a malicious push.
Not different from someone befriending a corporate employee and asking them to insert some malicious code into the codebase. You still rely on a web of trust - in the company's case, the code reviewers, in the open source example, the maintainers of the libraries that use left-pad. I don't think this argument really holds, I don't know what you're comparing it against that's different.
- always_good 9y agoWe'll have to agree to disagree if you see equivalence there. Even the smallest transitive dependency in our largest dependency graph in the Java ecosystem isn't someone's 6-liner afternoon project. I think the ease of publishing + ecosystem of small modules is a good thing, it just has what we consider an ecosystem-level security trade-off that matters for some applications.
- boomlinde 9y agoThe corporate employee is likely incentivized by a contractual obligation not to deliberately screw their employer over. There is a web of trust, sure, but don't pretend that it's somehow equivalent to betting that some rando on the internet doing whatever they feel like with their three line repo won't break your code.