4 ms·
Can I ask, is the Node ecosystem different in this respect to PyPI for example? Or is it not different at all and the same thing could (does?) happen there too?
by aigo 5y ago
Can I ask, is the Node ecosystem different in this respect to PyPI for example? Or is it not different at all and the same thing could (does?) happen there too?
- c0wb0yc0d3r 5y agoI'm not sure what countermeasures that project has in place, but there are plenty of articles exploring malicious packages found there.
- bscphil 5y agoThey're really quite different in my experience, but the difference is not one of availability so much as it is Python developers (mostly) following traditional software engineering best practices. I write almost all my hobby projects in Python. Very rarely do I incur a dependency tree involving more than a dozen projects while doing so. The rm -rf vulnerability is essentially a problem with a chain only being as strong as its weakest link. If any of the maintainers in the hundreds of node dependencies your project uses is malevolent, you're screwed. Hence, the security of the chain depends much more on the number of links it has rather than its innate strength. Even large and complex dependencies tend to be well engineered in Python. BeautifulSoup is a widely used library for loosely parsing HTML. It requires only Python and an internal library. lxml is another HTML parser (which BS can optionally use), and it requires only Python and a couple of C libraries. Even an entire web framework (Flask) uses only 4 Python dependencies directly and only one of these (the Jinja template engine) has recursive dependencies on other Python packages. All told it's about 10 Python packages needed in total. Or consider this, if you want an example of a trivial command line tool: the Python tldr[1] client uses only 3 libraries as recursive dependencies. The Rust client, tealdeer, has 119. The official nodejs client has, if I'm counting correctly, 603. [1] https://tldr.sh/ https://tldr.sh/
- aigo 5y agoThanks for this.