4 ms·
Not mentioned but this also gets them away from what now seems monthly npm supply chain attacks. Big win for security
by akmarinov 21d ago
Not mentioned but this also gets them away from what now seems monthly npm supply chain attacks.
Big win for security
- simonhamp 21d agoYou don't have to ditch cross-platform building entirely just to escape dependency hell
- akmarinov 21d agoNo, but it’s a nice bonus
- hn993302 21d agoDo you even escape dependency hell this way?
- msephton 21d agoIt's a developer decision. But I'd say it's easier to not use dependencies on native because there are more capable system API. I don't use any in my iOS apps, and only one dependency in 20 macOS apps.
- akmarinov 21d agoYeah, with iOS for example, you typically need very little third party dependencies for functionality. The main ones are things like analytics, crash reports, etc I’m not aware of any attacks on native package managers in the past 5 years. The closest would be a poisoned Xcode build in China that wasn’t downloaded from Apple a while back. Also getting an attack on one of the platforms means at least ~half your users are safe on the other one.
- hn993302 20d agoI remember there being a lot of hijacked CocoaPods more recently than that Xcode attack. But supposedly Swift Package Manager is actually replacing CocoaPods now, which tbh I didn't even know until now because I've been out of that loop. So that's good. One of my larger gripes with native Mac/iPhone dev was always needing to rely on a third-party package manager with all its quirks.