Comment on Roblox Game Devs Duped by Malicious npm Packages
colonial@lemmy.world 1 year agoTrue, but it’s uniquely bad in the JS world. Developers tend to rely on libraries in almost cartoonish excess.
- The language is shit in general, leading to an endless parade of frameworks and packages designed to paper over the sore spots.
- The lack of a well-rounded One True Standard Library™ means lots of trivial functionality needs to come from somewhere.
- Micro-dependencies are commonplace, leading to bloated dependency trees. I’d guess this is caused by a combination of both culture and the fact that you often want your JS artifacts to be as lean as possible.