3 ms·
That's beyond ridiculous, as an ecosystem. There is zero means for a user of npm to audit packages end-to-end. Is anyone attempting to improve upon this poison
by nullindividual 2y ago
That's beyond ridiculous, as an ecosystem. There is zero means for a user of npm to audit packages end-to-end.
Is anyone attempting to improve upon this poisoned web of packages?
- ssahoo 2y agoIt's only getting worse overtime. I have been advising devs to do more at code reviews. Every time a new package gets added or upgraded, that needs dual sign-off to justify it's use.