You must log in or # to comment.
Would be funnier without the LLM slop
Where’s that slop image coming from? Did you seriously generate a slop image to add to this post?
“npm” is an abbreviation of the package vetting methodology.
No Process, Motherf***er
Do other packe manager prevent this?
it has nothing to do with the package manager and everything with JS being a very widely used language mostly by rather inexperienced web devs.
The problem isn’t the package manager. Many small dependency packages multuply the attack surface of the “supply chain”. (it isn’t even a supply chain when a dude opensources his code as-is then a company decides to build their whole business on it)
I pulled in a webcomponent at work and got 300 plus deps. Fml.




