I barely never see anything about other package indexes (crates.io, PyPI, etc).
Doesn't npm also use a lock file by default for packages?
I barely never see anything about other package indexes (crates.io, PyPI, etc).
Doesn't npm also use a lock file by default for packages?
First, the scale of the JavaScript ecosystem. JavaScript is so much larger than every other ecosystem, so even a very small probability event (somebody introducing malware into a package) can happen surprisingly often given the scale of the ecosystem. Supply chain attacks are a problem in all open source ecosystems – not just JS – but they are a bit rarer and don't effect as many people so fewer people take note.
Second, npm was one of the first package managers to solve the classic "dependency hell" problem. In Python, if you have two dependencies, A and B, which both depend on different versions of C, say C@1.0.0 and C@2.0.0, respectively, then you're in trouble. You have an broken project. Python can only install one version of C. So now you're in dependency hell.
Npm on the other hand just installs both versions of C and it gives A the version that it wants, C@1.0.0. And it gives B the version that it wants, C@2.0.0. Both packages are happy - problem solved.
This caused Python maintainers to think twice before adding a new dependency lest they cause "dependency hell" for their users. Much better to just copy paste these 50 lines of code rather than adding a dependency. So there was an intrinsic sort of resistance – some pain is involved in adding new dependencies.
Npm maintainers had no such constraints. In a way, npm’s better developer experience led to the whole module ecosystem scaling "too well".
Disclosure: I started Socket (https://socket.dev) to help solve open source supply chain security. To learn more, see: https://news.ycombinator.com/item?id=30521913
Well, no, it's because the standard library is so good.
That's biased as hell but it's been my experience
I've seen plenty programmer's with CS degrees make terribly dumb mistakes, and some self-taught developers are some of the smartest people I've worked with.
There are more javascript developers, because JS is far and away the most popular programming environment due mainly to its ubiquity on the web. Because of that the JS supply-chain is a much larger attack surface than most languages.
Self-taught developers were once ardent hobbyists hailing from an era before (we had quite this much) aggressive commercialization of the internet. They found it fun to make computers blink pretty colors.
Self-taught developers today heard you could make a quick buck from the profession.
Industrial sabotage happens in most industries and JavaScript developers are no exception. This particular industry is huge. It contains millions of workers, some of which are politically motivated to engage in this kind of sabotage. The potential reach is even larger. And a well performed sabotage can potentially affect millions of people inside or outside the industry without putting the saboteur in that big of a risk.
I’m actually surprised we don’t see more of this.
If a transitive dependency (the majority of them) have changed, you're out-of-luck.