logoalt Hacker News

psadauskasyesterday at 9:05 PM5 repliesview on HN

If only the company behind VSCode, the company behind NPM and the company behind GitHub could get together and figure out a solution to this.


Replies

lackeryesterday at 10:25 PM

Perfectly demonstrating the truth of the "Microsoft org chart" cartoon.

https://bonkersworld.net/organizational-charts

show 1 reply
ozimyesterday at 9:45 PM

It is also company behind NuGet.

Guess what they did a year ago.

They removed 700 or so packages from NuGet proactively but those turned out to be false positives.

It is hard to do the right things.

show 2 replies
getpokedagainyesterday at 11:57 PM

Not trolling here but these things are by design cesspools ready for compromise. Any fully open ecosystem where contributions are not strictly reviewed is open to this problem. If you don't like it, don't use editor extensions and use a well audited editor.

If you want to use extensions or node packages or pypi packages without doing a detailed review you're accumulating technical debt. You're assuming a risk in order to ship rapidly. You can either pay that down at some point under control, or bear the interest when it comes due.

sieabahlparkyesterday at 11:09 PM

[dead]

notnmeyeryesterday at 9:22 PM

i mean, then you say it like that…

show 1 reply