Mastodon Feed: Post

Mastodon Feed

Boosted by soatok@furry.engineer ("Soatok Dreamseeker 🔜 Megaplex"):
joepie91@slightly.tech ("Sven Slootweg, ("still kinky and horny anyway")") wrote:

you would not *believe* how hard npm had to be dragged by the hairs to do literally *anything* about their piss poor security, or for that matter anything else with negative externalities, and that's *after* a 'package manager for the community' magically turned into a VC-backed startup somehow

the only reason npm has any sort of security mechanisms at all nowadays is basically that they got bought by microsoft, who had to at least look like they were doing something

and they kept banking on that "for the community" goodwill for many many years while raking in millions of VC