5 ms·
Not the OP, but my understanding is that the problem is a matter of practice: there are so many tiny packages with such complicated dependency graphs that the e
by c256 7y ago
Not the OP, but my understanding is that the problem is a matter of practice: there are so many tiny packages with such complicated dependency graphs that the exposed surface for attacks is two steps past gigantic.
As someone who doesn’t use much JS/npm, but who did work with dependency graphs in software systems in a former life, my (largely academic) study suggests that this is an intractable problem in npm — that is, a solution is such a big change from npm foundational usage that it’s far more likely to be solved with an npm replacement than an npm change. I would welcome sources that either refute or confirm this.