3 ms·
It’s correct that NPM is not unique but it is the worst for cultural reasons: no other ecosystem started with such a limited language, which lead to the culture
by acdha 2mo ago
It’s correct that NPM is not unique but it is the worst for cultural reasons: no other ecosystem started with such a limited language, which lead to the culture of publishing tons of small packages working around things which everything else had builtin. A Python project which has a hundred dependencies is considered quite large but the median React project had north of 30 thousand for years and years.
- insanitybit 2mo agoI think that's barely meaningful. Which of the compromised packages would have been part of any reasonable stdlib?
- acdha 2mo agoIt’s not that there’s a single stdlib feature which would’ve stopped this but more that JavaScript developers have been conditioned that it’s normal to install tons of packages and update them quite frequently so there are a lot of individual maintainers who if compromised have a surprising impact. You’re exposed as a function of the number of dependencies so the communities which most normalize many rapidly updating packages are going to be at greater risk. That’s not a simple trade off — that enterprise Java app which updates on a decadal cadence is still worse — but it means you need to accept the risk and use other mitigations.
- insanitybit 2mo agoI just don't think that this is that unique to javascript, it's absolutely not about npm, and I don't think that this is well supported as a relevant feature that leads to these attacks.
- acdha 2mo agoNobody is saying NPM is unique - it’s one end of a spectrum but that doesn’t mean everything else is completely on the other end - for example, this study found Maven projects having almost as many dependencies on average as NPM, both well ahead of everything else: https://arxiv.org/html/2512.14739v1 https://arxiv.org/html/2512.14739v1 Again, this is about culture rather than some innate flaw. Dependencies are about trust and I suspect that future developers are going to be amazed at how casually people ran code from strangers, similar to how stories about unprotected 70s swinger parties sound incredibly reckless to almost people who grew up after decades of HIV awareness campaigns.
- insanitybit 2mo ago> No way to prevent this says only package manager where this regularly happens "only"
- acdha 2mo agoThat’s a joke referring to The Onion, not a serious analysis: https://theonion.com/no-way-to-prevent-this-says-only-nation-where-this-r-1848971668/ https://theonion.com/no-way-to-prevent-this-says-only-nation...
- insanitybit 2mo agoHow much am I expected to charitably interpret the joke? They said "only", I'm taking it at face value because it's obviously intended to be commentary and the obvious implication is that this issue is unique to NPM (as that's the whole point of the Onion article). I'm well aware of the Onion reference.