You must log in or # to comment.
“Look at how all these much smaller package ecosystems don’t have the problems of the largest one.”
is the tl;dr of this article.
I made a wrapp er script named
npmon my $PATH that passes input topnpminstead because of this. I don’t think my team is ready to adopt something like that, but it seems to be working okay so far. Nobody has complained.Npm repos violate iso27002. So, it’s out. And we remember why iso27002 is important when we see news like this.
Oooh nice
