▲ | lycopodiopsida 3 hours ago | |||||||||||||
> Until you go get malware While technically true, I have yet to see Go projects importing thousands of dependencies. They may certainly exist, but are absolutely not the rule. JS projects, however... We have to realize, that while supply chain attacks can happen everywhere, the best mitigations are development culture and solid standard library - looking at you, cargo. I am a JS developer by trade and I think that this ecosystem is doomed. I absolutely avoid even installing node on my private machine. | ||||||||||||||
▲ | homebrewer 3 hours ago | parent [-] | |||||||||||||
Here's an example off the top of my mind: | ||||||||||||||
|