3 ms·
While Python being more widely used than JS, it's interesting the majority of attacks and breaches come from NPM. The consensus seems to be that Python offering
by nodesocket 1y ago
While Python being more widely used than JS, it's interesting the majority of attacks and breaches come from NPM. The consensus seems to be that Python offering a standard library greatly reduces the attack surface over JS. I tend to agree with this, a decently large Flask python app I am working on has 15 entries in requirements.txt (many of which being Flask plugins).
- Hasnep 1y agoThe large attack surface with npm is partly because of all the transitive dependencies used, which means that even if you only pull in a dozen packages directly, you're also using hundreds of other packages. Running `pip freeze` will list a lot of transitive dependencies as well, but I'm sure it'll be less than an equivalent JS project.
- zahlman 1y agoThe most important packages in the Python world don't have a lot of their own dependencies. Numpy has none, for example. The bulk of Numpy is non-Python code and interfaces/wrappers for that; the standard library isn't AFAIK pulling a whole lot of weight there.
- nwellnhof 1y agoNumpy depends on BLAS and LAPACK.
- milkshakes 1y agowhile those are obviously huge dependencies, i think the claim was about _python_ dependencies
- kinow 1y agoI also think the same. While in Java the stdlib lacks a few functions, long ago Apache Commons became the de-facto complement for the Java stdlib, being replaced/complemented by other libs over time, and eventually even becoming obsolete with newer versions of Java. But I always had the impression that having Apache Software Foundation components (with a good release/security process) helped Java to mitigate a lot of attacks.
- o11c 1y agoJavascript is also hindered by the fact that you have to "pay" for every library you download. This encourages a culture of reinventing the wheel, because "I don't need all that," preventing de-factor stdlib supplements from existing.
- magnio 1y agohttps://www.sonatype.com/blog/pytorch-namespace-dependency-confusion-attack https://www.sonatype.com/blog/pytorch-namespace-dependency-c... https://socket.dev/blog/pypi-package-disguised-as-instagram-growth-tool-harvests-user-credentials https://socket.dev/blog/pypi-package-disguised-as-instagram-... https://socket.dev/blog/monkey-patched-pypi-packages-steal-solana-private-keys https://socket.dev/blog/monkey-patched-pypi-packages-steal-s... https://socket.dev/blog/malicious-pypi-package-targets-discord-developers-with-RAT https://socket.dev/blog/malicious-pypi-package-targets-disco... https://socket.dev/blog/typosquatting-on-pypi-malicious-package-mimics-popular-browser-cookie-library https://socket.dev/blog/typosquatting-on-pypi-malicious-pack...