Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Pulling in lots of dependencies creates this kind of risk regardless of the ecosystem. That being said in the JS/NPM world you tend to have a LOT more dependencies (especially indirect ones) than other languages. I saw someone do a cursory analysis and JS/Node projects tend to have 5x the number rust or ruby projects.

This is really a cultural problem not a technical one.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: