| ▲ | isopede an hour ago | |
Pretty much every modern language with a package repository is vulnerable to supply chain attacks. Are there any languages doing something unique or are especially resilient in this respect? | ||
| ▲ | slowin 13 minutes ago | parent [-] | |
You can get a binary compiled by the author or a trusted source and none of the dependencies can change out from under you. This isn't possible with an interpreted language where the dependencies are resolved (often from dubious places like npm) at install and update time. | ||