3 ms·
I suspect a huge fraction of those packages need to be rolled up into a standard library for which some foundation can take money and do proper release engineer
by gnu8 5y ago
I suspect a huge fraction of those packages need to be rolled up into a standard library for which some foundation can take money and do proper release engineering.
- qudat 5y agoBut then aren’t you still trusting a third-party to properly audit their own code and ensure it doesn’t get compromised? Where’s the line?
- totony 5y agoIt's easier to trust 1 org than 1000 different developers.
- Zababa 5y agoYou have to trust someone at some point. I think that was part of the point of the "Reflections on Trusting Trust" lecture.
- gnu8 5y agoI don't know where the line is, but I know users of eg Debian don't find trojans and cryptominers appearing on their systems after routine updates. They have thousands of obscure packages, but they don't let just anyone upload something.
- GordonS 5y agoWhen these compromised npm packages happen, the blast radius would be a fraction of what it is today if the JavaScript standard library wasn't so anaemic.