4 ms·
I think the issue with npm is that it makes what should be a relatively important task (adding huge swathes of mostly unknown code) trivial to do, leading to al
by SQueeeeeL 4y ago
I think the issue with npm is that it makes what should be a relatively important task (adding huge swathes of mostly unknown code) trivial to do, leading to all the bloat and abuse that ecosystem has seen. Sometimes a bit of friction that forces the user to slow down and truly understand what they're doing is a good thing...
- shadowgovt 4y agoThe vulnerable part of the npm ecosystem is trust and end-user high-granularity control of trust. If that problem can be solved, there's nothing inherently problematic with just using large swathes of mostly unknown code. Almost no Debian user knows the innards of every package they've installed, even the dev libraries they're building new applications on top of (to say nothing of every Ubuntu user). (TBF to the ecosystem, there actually is a mechanism for flagging security issues in old library versions and surfacing those to a package builder. But it is up to the package builder to account for them by changing their dependencies).
- __MatrixMan__ 4y agoI agree. To be more specific I think the problem with npm is that it explicitly trusts names and implicitly trusts their referents, which puts too heavy a burden on the name resolver. Contrast this with apt, which inspects package signatures and compares them to keys I've trusted. If a package shows up with the same name as before, but different bits, and it's signed by somebody new, I have a reason to scrutinize it more heavily.