4 ms·
One could extend that logic to argue that all package managers are red flags: after all, you're downloading third-party code from external servers; you just hap
by candu 6y ago
One could extend that logic to argue that all package managers are red flags: after all, you're downloading third-party code from external servers; you just happen to be doing it ahead of time, rather than at runtime.
In principle, there's no reason why the same supply-chain security mitigations npm and other package managers / repositories have put in place could not also be applied in this case: you just apply them at download time, same as before, except now it might result in a runtime error instead of an npm install failure. (No idea if deno does this in its current state, tbh.)
Agree, however, that blindly executing third-party code without somehow vetting it is a security risk.
Also, re: Python - there's a reason why libraries like requests exist; while the Python Standard Library is pretty comprehensive, the APIs it exposes are not always the most intuitive. You might be surprised at how often people pull in helper libraries to work around some of its warts - now, one could argue that maybe they shouldn't do that and should just know the built-in modules better, just as one could argue that functionality is useless unless combined with usability.
- jfkebwjsbx 6y agoPackage managers are not red flags, the packages, its vendors and procedures behind those are. When you download a software update for your kernel you are trusting the Linux Foundation and your upstream vendor. They are supposed to have proper processes in place, they sign the binaries and may even have a support contract with you. When you put a random URL as a dependency, you are just trusting some random person over the Internet not to screw it up. Re: Python libraries. The topic of this thread was about "small scripts and tasks". The point of Python and its "batteries included" is that you don’t need external libraries to accomplish common tasks. It is a mistake to use external helper libraries in your scripts (not apps).