3 ms·
How is `node_modules` different from `/path/to/venv/lib/python3.X/site-packages` ? Are PyPI, cargo, Maven, etc... all immune to supply chain attacks?
by linkdd 3y ago
How is `node_modules` different from `/path/to/venv/lib/python3.X/site-packages` ?
Are PyPI, cargo, Maven, etc... all immune to supply chain attacks?
- rcfox 3y agoOne major difference is a venv doesn't allow nested dependencies. With npm, you might install version 2.3 of a package, only to find that some other package has installed version 1.4 under itself. Python also has "wheels", which are pre-compiled distributions, rather than full-source distributions. These are often smaller and install faster.
- heywhatupboys 3y ago> One major difference is a venv doesn't allow nested dependencies. With npm, you might install version 2.3 of a package, only to find that some other package has installed version 1.4 under itself. a feature not a bug. Anyone who ahs built a sufficiently large project and had to abandon some dependencies know this pain