4 ms·
NPM is not trusted by major fortune enterprises. Many of the tech companies I've worked at banned using NPM in prod. And instead created their own NPM Clone wit
by cobookman 6y ago
NPM is not trusted by major fortune enterprises. Many of the tech companies I've worked at banned using NPM in prod. And instead created their own NPM Clone with source code pinned into a private repo, which security audited.
Adding a single NPM library became a total PITA, as it linked to another 100 other NPM libraries, which in-tern linked to an additional 100+ other NPM libraries. So adding a single NPM library to the private repo, meant adding 100s to 1000s of other NPM libraries. (E.g. left-pad [1])
Personally, I think this was a major reason for node.js not picking up more in the enterprise space. With Python & golang getting more traction.
[1] https://qz.com/646467/how-one-programmer-broke-the-internet-by-deleting-a-tiny-piece-of-code/ https://qz.com/646467/how-one-programmer-broke-the-internet-...
- mandelbrotwurst 6y ago> With Python & golang getting more traction. Does pip not have the same issues?
- dgellow 6y agoPython and go have similar issues though. People do not audit and do no vendor their dependencies.
- jniedrauer 6y agoAt least python and go packages don't execute arbitrary code on developer's workstations at install time. If you pin dependencies to a known safe version, then you're relatively safe. With NPM, just typing `npm update` can pwn your workstation.
- rnestler 6y agoFor Python this is only true for wheels packages. Source packages may execute arbitrary code in setup.py during pip install (compiling C code for example).
- mytherin 6y agoWhat is the fundamental difference between pip and npm here? `pip install` will run whatever is in the `setup.py` of the package (and recursively do the same with any dependencies). That is essentially arbitrary code execution, no? This feels more like a numbers issue than a fundamental difference, i.e. Python packages generally have orders of magnitude fewer dependencies than JS ones because the standard library is very extensive. Most dependencies are major libraries rather than small ones, which are much less likely to be compromised.
- twistedpair 6y agoI wonder how many enterprises can afford that? I know of one that had a security team that was supposed to approve all dependencies, but it became a joke because it took them forever to approve a package or update, so patches weren't approved in a timely manner. The security workload had the reverse effect of making many builds less secure. There does seem to be a market opportunity though, for a curated, "blessed" clone of NPM for enterprises to pull from.