3 ms·
> I feel like there are still too many hands in this particular cookie jar. MFA or no. On average, how many other organizations & human developers are somehow i
by joekrill 4y ago
> I feel like there are still too many hands in this particular cookie jar. MFA or no. On average, how many other organizations & human developers are somehow involved in the dependency graph of a modern node.js project?
What does that really matter, though? You could ask the same of _any_ modern application, NodeJS or otherwise: "On average, how many other organizations & human developers are somehow involved in the dependency graph of a modern application?". Look at your web browser alone. You have an open source rendering engine. The JavaScript engine. The underlying libraries used to handle things like SSL, TCP/IP, DNS lookups. It runs on an OS that likely has layers and layers of open source code. Which runs on hardware from various manufacturers with firmware written by many people spread across many organizations.
- Santosh83 4y agoThe difference is people have become conditioned to trust corporations and organisations, so the software/hardware you mentioned have people or addresses who must answer if they get compromised. Whether they answer is a different thing, and whether this is a good model for everyone is another question. NPM packages on the other hand are dependent on random individuals for integrity and society doesn't trust individuals as much as registered entities, especially profit making ones.