Is this our chance to stop using NPM?
Is this our chance to stop using NPM?
Posted Jun 1, 2026 18:07 UTC (Mon) by ibukanov (subscriber, #3942)In reply to: Is this our chance to stop using NPM? by yodermk
Parent article: Multiple redhat-cloud-services npm packages compromised (StepSecurity Blog)
It was specifically JS that ended up with huge number of tiny packages vastly increasing the chance of compromise. I do not think it was just language popularity but specifically language features like tiny standard library and the way external modules are loaded that lead to this. Plus NPM made it too easy in retrospect to create and submit a package.
