Reply to post: Build time internet dependencies are garbage

Check your repos... Crypto-coin-stealing code sneaks into fairly popular NPM lib (2m downloads per week)

asdf

Build time internet dependencies are garbage

Guess I am old but I can't see ever supporting a code base whose build system relies on the internet at build time. 3rd party libs and external dependencies are going to be managed in-house only if its my butt on the line. Others outside your repo should not be able to break your builds. Granted would see same problem when you bring in broken code yourself but at least you can easily roll back and not depend on others to fix your build.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon