Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't really buy this. NPM is targeted because it's the largest attack surface with the biggest payoff for a successful attack.

Other ecosystems package managers are really no different in a lot of ways.

NPM's biggest fault is just it allows post/pre install scripts by default without user intervention.

 help



Your last two sentences are contradictory. That is a very significant difference.

Another significant difference is how useful the standard library of each language is, so that you can avoid 3rd party libraries.

Also the tendency in the JS ecosystem to break libraries into tiny parts, because it helps or historically helped to ship less code to the user.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: