Scan to Download Gate App
qrCode
More Download Options
Don't remind me again today

Interesting observation here. Been maintaining 300+ packages with over a billion downloads combined, yet zero security incidents on my end.



Maybe it's because I'm cautious about what gets merged. Most packages go through complete testing cycles, full documentation, and they're actually finished before release.

Here's the thing though - NPM itself is becoming a vulnerability. And honestly? We might not even need it in the first place.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Repost
  • Share
Comment
0/400
ImpermanentPhilosophervip
· 13h ago
This guy is right, the npm ecosystem is like a ticking time bomb, worrying every day about which package will blow up again.
View OriginalReply0
LiquidatedDreamsvip
· 12-01 16:04
Nah, this guy really held it together... 300+ packages, zero incidents, what does that indicate? It means there are still a few people who are serious about their work.
View OriginalReply0
LiquidationSurvivorvip
· 12-01 16:02
The pro's technique is indeed ruthless; having over 300 packages with zero accidents is something worth bragging about for a lifetime.
View OriginalReply0
SchroedingersFrontrunvip
· 12-01 15:55
The npm ecosystem is bound to collapse eventually; relying on self-discipline to maintain the current state is too fragile.
View OriginalReply0
DaoResearchervip
· 12-01 15:49
From the voting data of governance proposals, the vulnerability of NPM's centralized architecture has been confirmed, and the decentralized package management DAO governance solution is worth exploring.
View OriginalReply0
PriceOracleFairyvip
· 12-01 15:48
ngl the npm dependency graph is basically an oracle manipulation waiting to happen... 300+ packages with zero incidents? that's the kind of statistical anomaly that makes me wonder if you're just flying under the radar or actually operating in a different market inefficiency than everyone else lmao
Reply0
TopBuyerBottomSellervip
· 12-01 15:44
Wow, this guy is right, npm should have changed a long time ago.
View OriginalReply0
  • Pin
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)