• hersh@literature.cafe
    link
    fedilink
    English
    arrow-up
    11
    ·
    16 hours ago

    I don’t think you’ll find another major repo with so many real-world incidents though. Whether this is because of a systemic problem or just because it’s targeted more frequently, I’m not sure.

    • tempest@lemmy.ca
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      5
      ·
      16 hours ago

      As much as some people deride it Javascript is one of the most used languages on the planet.

      This is basically the same as people thinking windows is less secure because it’s more often targeted.

      JavaScript does have a bit of a problem with dependencies but it isn’t much different than other languages with built in package managers like rust. It’s just a bigger juicer target.

      • aesthelete@lemmy.world
        link
        fedilink
        English
        arrow-up
        12
        arrow-down
        1
        ·
        edit-2
        10 hours ago

        But Windows is less secure. Two things can be true at once. They are in the original topic too.

        The Java ecosystem is massive and decades old and I don’t hear one iota of the shit about maven central that I hear about npm.

        I guarantee that npm is full up with vibe coded bullshit at this point as well.

        I’m not sure what it even takes to upload a package to npm. Not even a pulse. I honestly never looked into it because the whole ecosystem is so rancid.

        EDIT: Look at how many shits in this are optional (and note the overall quality of the article as well): https://dev.to/aneshodza/publishing-your-first-npm-library-51k2. The ecosystem sucks.