baldur
baldur

Idle thought: most Open Source Software, certainly most OSS on npm, shouldn’t be OSS but should instead be educational resources: blog posts, online courses, video tutorials, etc. You’d both have fewer burned out OSS maintainers and fewer dependency exploits that way.

|
Embed
Progress spinner
pimoore
pimoore

@baldur My understanding is that NPM has had a terrible track record in terms of exploits, more so than other open source repositories.

|
Embed
Progress spinner
In reply to
toddgrotenhuis
toddgrotenhuis

@pimoore can confirm

|
Embed
Progress spinner
baldur
baldur

@pimoore Yeah. Although I’m not sure how much of that can be attributed to npm’s design and how much of it is either its sheer size or bad habits in the JS/node community.

Or all of the above?

|
Embed
Progress spinner
pimoore
pimoore

@baldur Probably all of the above. It makes me wonder about the safety of any projects that rely on npm/node libraries, which seems to be a lot more as of late.

|
Embed
Progress spinner