• Aniki@feddit.org
      link
      fedilink
      English
      arrow-up
      4
      ·
      22 hours ago

      it has nothing to do with the package manager and everything with JS being a very widely used language mostly by rather inexperienced web devs.

    • kopasz7@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      The problem isn’t the package manager. Many small dependency packages multuply the attack surface of the “supply chain”. (it isn’t even a supply chain when a dude opensources his code as-is then a company decides to build their whole business on it)