Comment on NPM Package With 56K Downloads Caught Stealing WhatsApp Messages
tux0r@feddit.org 8 hours agoThis isn’t going to get any better unless we revert to OS based dependencies which noone wants to do because developers want the latest and greatest model.
A few operating systems (e.g. OpenBSD) do actually (try to) enforce using pkg for Perl dependencies, due to Perl being “system Perl” instead of “packaged Perl”.
wildbus8979@sh.itjust.works 8 hours ago
Debian does as well for anything that is packaged. For python, golang, rust, etc as well.