Hacker News new | past | comments | ask | show | jobs | submit
> NPM is by no means the worst offender here

Ok, I can agree it is a boring comment, but who is worse?

NPM gets targeted both because it is popular and because there is a wider attack surface (lots of little packages promoted by a huge variety of users) I have a high schooler who published work a couple weeks ago. This is good, but it comes with downsides. Maybe a couple more speed bumps or classifiers would be helpful. Maybe a consolidation of under maintained projects and deprecation is in order.

Arguably crates.io is worse. NPM has cooldowns and has for a while, it has had Trusted Publishing for longer, it has human-approved releases that separate CI/CD from actual publishing. Ruby is probably worse in every way.
RubyGems actually adopted Trusted Publishing before both npm and crates.io. To my recollection, they were second after PyPI.

(I have no opinion about the overall security posture of these indices.)

loading story #49172258