4 ms·
They are language-independent but may still have a higher incidence in one community than another. Anecdotally, these basic mistakes seem to happen more in Node
by grumdan 8y ago
They are language-independent but may still have a higher incidence in one community than another. Anecdotally, these basic mistakes seem to happen more in Node packages or JS-based projects, but I have no concrete evidence for this speculation. The only study I know of looking at this in a serious way is this one:
http://web.cs.ucdavis.edu/~filkov/papers/lang_github.pdf http://web.cs.ucdavis.edu/~filkov/papers/lang_github.pdf
(https://news.ycombinator.com/item?id=8558740 https://news.ycombinator.com/item?id=8558740)
However, JavaScript ends up a being less prone to defective commits than C++ and C, as well as PHP and Python, but there are a number of issues that don't allow us to conclude all that much from these results (imo).
- staticassertion 8y ago> Anecdotally, these basic mistakes seem to happen more in Node packages or JS-based projects It's just bias. Python code is riddled with vulns - especially since it's all C under the hood. https://hackernoon.com/python-sandbox-escape-via-a-memory-corruption-bug-19dde4d5fea5 https://hackernoon.com/python-sandbox-escape-via-a-memory-co... Here's a great post that covers some issues in Python modules and why they're extra exploitable because they execute under CPython. This is a particularly relevant quote: > Perhaps less recognized is the fact that memory corruption bugs are reported in popular Python modules all the time without so much as a CVE, a security advisory, or even a mention of security fixes in release notes.