Comment on Why is the Node ecosystem so demanding?

ono@lemmy.ca ⁨1⁩ ⁨year⁩ ago

My take: It’s because the “trust everything from everybody” model is fundamentally broken.

Note that the “trust” here is not only about avoiding malicious or vulnerable code, but also about dependability. Even if you ignore the “supply chain” security problems inherent in this model, it practically guarantees that breakage like this will happen.

This is part of why I prefer languages with robust standard libraries, and why I am very picky about third party dependencies.

source
Sort:hotnewtop