3 ms·
I wonder how many enterprises can afford that? I know of one that had a security team that was supposed to approve all dependencies, but it became a joke becaus
by twistedpair 6y ago
I wonder how many enterprises can afford that? I know of one that had a security team that was supposed to approve all dependencies, but it became a joke because it took them forever to approve a package or update, so patches weren't approved in a timely manner. The security workload had the reverse effect of making many builds less secure.
There does seem to be a market opportunity though, for a curated, "blessed" clone of NPM for enterprises to pull from.