logoalt Hacker News

altcognitoyesterday at 7:02 PM1 replyview on HN

> the framing that npm is so bad is really flatly invalid.

Is it really though if we're getting thousands of compromised packages regularly?

You can do all the right things and still be legit problematic.


Replies

insanitybityesterday at 7:55 PM

Yes, it has nothing to do with the design of npm (relative to similar languages/ repositories) and everything to do with the popularity.