61
top 5 comments
sorted by: hot top controversial new old
[-] minfapper@piefed.social 5 points 21 hours ago

"Look at how all these much smaller package ecosystems don't have the problems of the largest one."

is the tl;dr of this article.

[-] esc@piefed.social 1 points 7 hours ago

Npm having a lot of packages at least partially a problem of lacking standard library, no? And partially developer culture where every trivial thing is a package. Anyway, similar thing will happen to rust soon enough (*looks at 1 gig of dependencies for a cli program*).

[-] numbermess@fedia.io 6 points 1 day ago

I made a wrapp er script named npm on my $PATH that passes input to pnpm instead because of this. I don't think my team is ready to adopt something like that, but it seems to be working okay so far. Nobody has complained.

[-] corsicanguppy@lemmy.ca 5 points 1 day ago

Npm repos violate iso27002. So, it's out. And we remember why iso27002 is important when we see news like this.

[-] sudoMakeUser@sh.itjust.works 5 points 1 day ago
this post was submitted on 16 May 2026
61 points (100.0% liked)

Hacker News

4870 readers
496 users here now

Posts from the RSS Feed of HackerNews.

The feed sometimes contains ads and posts that have been removed by the mod team at HN.

Source of the RSS Bot

founded 2 years ago
MODERATORS