You must log in or register to comment.
Fizz@lemmy.nzEnglish
55 minutesI’m not familiar with npm but why is this always NPM? Is it a specific issue they have?
BoofStroke@sh.itjust.worksEnglish
44 minutesIt’s a “package manager” that has zero integrity checks built in. Web devs also love it. Nice combination.
- NotSteve_@lemmy.caEnglish40 minutes
I don’t really see how it’s NPM at fault here. This was caused by a malicious actor taking control of an account and putting out bad packages on it. It could happen on any package repository for any language
- homes@piefed.worldEnglish1 hour
One day, back in 1995, I could download every red hat package onto a series of 13 floppies.
In fact, it was required if you wanted to install red hat. So was compiling them all onto your own computer.
How far we’ve come



