4 ms·
AFAIK the real problem in node is not number of packages in itself, but number of independent trust relationships implied by transitive dependencies. Basically
by JackC 7y ago
AFAIK the real problem in node is not number of packages in itself, but number of independent trust relationships implied by transitive dependencies. Basically how many separate people's integrity and security practices are you counting on when you install your reqs?
So a language could:
- identify a blessed set of packages that don't imply separate trust relationships (a stdlib, or packages maintained or audited by the language team)
- require strong security practices and/or trust metrics from package authors
- clearly expose the full list of authors implicitly trusted by a requirements file
- offer community auditing tools, such as reproducible builds if delivering compiled files, web of trust tools, or diff tools
- run internal tests for suspicious packages (and don't talk about them)
If you frame the problem differently the solutions might be different, but I suspect there would still be a bunch of options.