I’m now a firm believer that every package manager needs to support hooks globally.
Composer also supports conflicts which results in this amazing approach of having a meta-package conflict with insecure packages: https://github.com/Roave/SecurityAdvisories.
Can’t happen in Node, sadly because of language differences.
moebrowne 1 days ago [-]
I appreciate Composers slower but deliberate, well thought out approach to supply chain attack mitigations.
Rendered at 16:25:46 GMT+0000 (Coordinated Universal Time) with Vercel.
I’m now a firm believer that every package manager needs to support hooks globally.
Composer also supports conflicts which results in this amazing approach of having a meta-package conflict with insecure packages: https://github.com/Roave/SecurityAdvisories.
Can’t happen in Node, sadly because of language differences.