• kopasz7@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 days ago

    The problem isn’t the package manager. Many small dependency packages multuply the attack surface of the “supply chain”. (it isn’t even a supply chain when a dude opensources his code as-is then a company decides to build their whole business on it)