▲ | A better future for JavaScript that won't happen(drewdevault.com) | |||||||||||||
19 points by ingve 19 hours ago | 4 comments | ||||||||||||||
▲ | pjmlp 17 hours ago | parent | next [-] | |||||||||||||
> Maybe other languages that depend on this broken dependency management model, like Cargo, PyPI, RubyGems, and many more, are watching this incident and know that the very same crisis looms in their future. Maybe they will change course, too, before the inevitable. Unfortunely no, that is why SBOM (Software Bill Of Materials), and only allowing vetted software packages on in-house CI/CD is such a thing on many companies. Unfortunely not yet spread wide enough, and anyway doesn't do anything for everyone else doing software outside big corporation virtual wall. Most developers are too trigger happy to add software dependencies without thinking twice about them. | ||||||||||||||
▲ | giveita 19 hours ago | parent | prev [-] | |||||||||||||
It is a lot of work to make a web standardised standard library for JS. Probably years of work. Any decision is set in stone. You cant pull python 2 to 3 or the various .NETs for open standards the world relies on. It is a hard problem. Worth starting on maybe but wont be ready for a long while. | ||||||||||||||
|