Comment on NPM Package With 56K Downloads Caught Stealing WhatsApp Messages
PushButton@lemmy.world 6 hours agoMaven entered the room.
Comment on NPM Package With 56K Downloads Caught Stealing WhatsApp Messages
PushButton@lemmy.world 6 hours agoMaven entered the room.
wildbus8979@sh.itjust.works 6 hours ago
I’m not super familiar with Maven so I could be wrong, but doesn’t Maven still pull depencies from upstream? That doesn’t fix the problem. Having depencies packaged in the OS means there is in theory some level of overview and review by the package maintainer(s).
PushButton@lemmy.world 5 hours ago
I am on my phone, which is a bit too long to explain, but there are multiple facets to how NPM is worse than most packaging systems out there. There are enough on the web for you to browse and learn, if you are really interested to know more.
But, here, I quoted a little something from Brian from Sonatype.