• dustyData@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    7 hours ago

    Any security system based on expecting good behavior from people is sure to fail. If NPM has no estructural features to enforce safe behaviors, it is vulnerable by default. As no person using it will apply safe practices unless forced to. Specially if the default, easiest, less friction behavior, is inherently unsafe.

    • LurkingLuddite@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 hours ago

      I wouldn’t say pulling in higher versions is unsafe unless an attack like this succeeds. Otherwise it’s only an annoyance.