6 ms·
Personal attacks are completely unwarranted. I think a more useful (and certainly more constructive) way to look at this is to frame it as a learning experience
by davej 8y ago
Personal attacks are completely unwarranted. I think a more useful (and certainly more constructive) way to look at this is to frame it as a learning experience and figure out what we can do to minimize the effect of this in future.
It's almost impossible to vet every sub-sub dependency of a large codebase without dedicating huge resources. Perhaps there needs to some sort of a javascript code signing standard that requires a level of user identity verification. This is a solved problem with Authenticode and Gatekeeper for executables on Windows/Mac. We have been able to hide behind the fact that we're devs (we know what we're doing!!), but many consumer-level applications (mainly Electron-based) now run node modules with user-level (or higher) permissions. Maybe we need to become a bit more diligent in this area and look at less ad-hoc ways of managing dependencies and identity verification.