Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In the context of build systems and the vulnerabilities that exist in xs, one of server-side JavaScript’s biggest footguns that cannot be ignored is its dependency management. Very few people I know ever really dig into the dependency tree and audit all packages 10 levels deep. The attack surface there is huge and objectively much wider than PHP/Bash. It’s also a built-in automatic entryway into a corporate network.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: