36 karma · joined April 4, 2023
Maybe one of the ways is to identify with the shine and the image differences since fat floats on top. But then how do we add a quantitative metric to it as in how many tbsp of butter were used?
to clarify if I understood correctly, because packages would be fragmented and hence more attack vector?
I like the spirit of article however,
1. Tracking every mention of a dependency and assigning value fairly is extremely hard: many packages are widely reused while many are tiny utility libs.
2. Usage in a file doesn’t reflect actual runtime usage. A repo might list a package but never import it.
Overall, solutions that align incentives, and maintain ecosystem neutrality are more likely to gain traction than a platform-wide mandated surcharge.
I do see ads on your website, is it high traffic as well?
Also, backed by science, they have been increase in nutritional studies since 2010s, the same orange which our grandma consumed, had 5x more nutrition than the ones we eat today just because of the genetic modifications we have done over the years. So yes, being on the same diet we may need more fitness and hence the recent popularity
>Contextualize the actual risk This is not as easy as it seems, for example reflection cases where runtime behavior affects a package usage. example: const lib = require(process.env.PARSER) lib.parse(userInput) could use a safe parser in production or a vulnerable one in another environment, but from a code level perspective there's no certainity which package is actually used