Friday 30 November 2018

ELI5: Why is npm a “broken” system security wise, compared to other package managers?

Why does npm get a lot of sh*t, compared to other package managers security wise? Why does something like event-stream happen on npm but not other package managers? Wouldn’t it be also as easy to publish a malicious e.g. pip package as on npm?

Submitted December 01, 2018 at 01:53AM by BrunnerLivio

No comments:

Post a Comment