Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m not sure this would be smaller scale? At least probably too early to tell?


I just mean fewer total packages and fewer maintainers. Linux libraries and packages don’t have the culture of making a package out of a single small function and importing it everywhere, which is part of the reason why NPM is a good case study in opportunities for supply chain attacks.


Yes but the distribution likely depends on it, making it wider spread even without the middleman dependencies.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: