"Jer, it sounds like you just hate all package managers."

It just sounds that way because every goddamned one of them I have to interact with lets randos upload arbitrary shit that they didn't even write and then thousands of other people's packages suddenly depend on them.

@sullybiker I think we're saying the same thing: don't download packages from public package repositories, ESPECIALLY not in the process that deploys stuff to your site

@sullybiker what we have here is a web of trust: it anyone on the WEB can upload something, you can't TRUST it.

Follow

@nyquildotorg Yeah it is ripe for abuse and does get abused.

Sign in to participate in the conversation
Mastodon

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!