Skip to content

Comment on 70% of new NPM packages in last 6 months were spamparent

Comments

WA

It's two things really: a small standard library and sheer size of developer community. JS has way more developers than any other language. But if you search for "$PROGRAMMING_LANGUAGE supply chain issues" you literally find reports for all popular languages.

[1] claims that half of Python packages have security issues.

[2] says that the Rust supply chain has security issues.

just as two examples.

---

[1]: https://www.theregister.com/2021/07/28/python_pypi_security/

[2]: https://news.ycombinator.com/item?id=40864787

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.