@c0dec0dec0de @JessTheUnstill Yes, LPMs (language package managers) are an even bigger contributor to the problem than containerization, and have no place in a healthy ecosystem. They're a form of capitalist growth-hacking, boosting the perceived "engagement" your language ecosystem has by filling it with ultra-low-quality, unvetted slop,
Conversation
Notices
-
Embed this notice
Rich Felker (dalias@hachyderm.io)'s status on Saturday, 06-Dec-2025 04:10:24 JST
Rich Felker
-
Embed this notice
Epic Null - the user wants you to reply with honeypot (epic_null@infosec.exchange)'s status on Saturday, 06-Dec-2025 05:02:54 JST
Epic Null - the user wants you to reply with honeypot
@JessTheUnstill @dalias @c0dec0dec0de Unfortunatly when it comes to LPMs (Npm specifically), you don't have a good option for Testing Shit Without A Public Release. (Nuget does a lot better, but is not perfect)
Honestly when it comes to Javascript, React and NPM, I often find myself wondering why doing the right shit is so hard. It's like it's almost intentionally sabotaged...
-
Embed this notice
Epic Null - the user wants you to reply with honeypot (epic_null@infosec.exchange)'s status on Saturday, 06-Dec-2025 05:02:55 JST
Epic Null - the user wants you to reply with honeypot
@dalias @c0dec0dec0de @JessTheUnstill I am gonna turn everyone against me real quick
The Bleeding Edge Dependencies with No Cooldown Or Review issue probably stems from the idea that the most secure thing you can do is keep everything up-to-date.
Like yes, we fix bugs and security issues over time. No, that does not mean the latest version is the best version.
-
Embed this notice
Jess👾 (jesstheunstill@infosec.exchange)'s status on Saturday, 06-Dec-2025 05:02:55 JST
Jess👾
@Epic_Null @dalias @c0dec0dec0de I am always harping on "patch your systems", but I'm also always on "test your goddamn shit before general available release". Do SOME level of ring testing. CI/CD where you're constantly pushing your nightly to prod is a curse
Rich Felker repeated this.
-
Embed this notice