That’s a fair point, though are you sure about
most? And are you saying most code only comes in minified form, or are you referring to libraries that come with a pre-minified option in addition to readable source? I’ve used NPM a bunch and rarely seen minified code only, and usually minification happens on my end as part of my site’s build, not to obscure JS library source code.
It’s true that use of NPM requires trust. At least NPM projects have a name attached to them and some accountability. It is by no means foolproof, but malicious projects lose their accounts along with the reputation that takes time to earn. The world does seem to be okay with a certain amount of trust.
This is really true of any software distribution system, even and including all distros of Linux. The point at the top of the thread is that we don’t have a way to know what happens when we download any software, or when we give our data to an application. We can protect our computers by auditing software and sandboxing systems, but the system still requires trust. Open source and auditing is still just a narrative that I have to trust from my point of view, unless I’m the person doing the auditing myself.
It might help to clarify the threat model. The poster I replied to confused a security model with a privacy model. The thread above it was about privacy, not about security. There is no software distribution model anywhere that addresses what happens with my data on somebody’s backend once sent, nor whether they can share data that I enter into an application over the internet, right?