| ▲ | mayama 12 hours ago | |
Min release age might just postpone vulnerability to be applied few days later in non trivial cases like this. More I think about it, Odin lang approach of no package manager makes senses. But, for that approach won't work for Javascript as it needs npm package even for trivial things. Even vendoring approach like golang won't work with Javascript with the amount of churn and dependencies. | ||
| ▲ | tisc 8 hours ago | parent | next [-] | |
It does not _need_ it, that’s the thing. It has become a custom to import a dependency for a lot of things. Especially for JavaScript. | ||
| ▲ | 11 hours ago | parent | prev [-] | |
| [deleted] | ||