26 ms·
One of the reasons I've stayed away from Node is the ridiculous attack surface brought by the npm ecosystem. It seems that even the simplest of projects end up
by jsploit 7y ago
One of the reasons I've stayed away from Node is the ridiculous attack surface brought by the npm ecosystem. It seems that even the simplest of projects end up with hundreds of dependencies - most having different maintainers and security practices.
- johnisgood 7y agoHow does it compare to Rust's cargo and its crates? The above mentioned "small package that do a single thing" philosophy is rampant there as well.