When you (in Facebook's words) "Set up a modern web app by running one command", this is what happens: npm.anvaka.com/#/view/2d/rea…
4
69
14
110
And that wasn't even done with malintent. Imagine the attack surface an actual bad actor has access to.
I think practically all platforms have the problem of unmanaged, unaudited external dependencies. Node and NPM are just so particularly easy to make fun off
Jan 10, 2020 · 6:13 PM UTC
1
1



