4 ms·
For me, building production software in Deno - it's the sandbox that sets Deno apart. Knowing that even if there's a bad package, it can't call any external se
by tmikaeld 2y ago
For me, building production software in Deno - it's the sandbox that sets Deno apart.
Knowing that even if there's a bad package, it can't call any external server or write/read files from disk.
Even generally, I now know that the code I wrote don't do any unauthorized things I didn't explicitly tell it to do.
- alabhyajindal 2y agoHow common is this scenario really? I rarely find myself using obscure packages. Most of the ones I use are hugely popular and vetted by the developer community.
- thejazzman 2y agoTheir dependencies have dependencies which have dependencies and their dependencies dependencies' could be compromised If you think someone is reviewing all the code every time a new release is cut... popularity means it's one of the hottest targets.