When will we learn?

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A timeline of supply-chain attacks across npm, PyPI, Cargo, RubyGems, and other package registries is presented, arguing that these incidents are a predictable consequence of package managers that publish vendor-uploaded packages without independent review. The author contends that Linux distribution package managers solve this problem through independent maintainers, review processes, reproducible builds, and stable distributions, and challenges overlay package managers (npm, Cargo, PyPI, etc.) to adopt similar practices or be considered redundant.

3m read timeFrom drewdevault.com
Post cover image
Table of contents
Timeline of major incidents on npm/Crates/PyPI/etcTimeline of similar incidents in official Linux distribution repositoriesWhy is this happening?Can these package managers do it better?

Sort: