Dan Abramov 7/7/2021

npm audit: Broken by Design

Read Original

This article argues that 'npm audit' is fundamentally broken by design. It criticizes its rushed rollout as a default feature, its inadequacy for front-end tooling, and the 'cry wolf' effect of its warnings. The post explains how the tool works, why its current implementation is problematic, and what changes the author hopes to see to fix the security tool for the npm ecosystem.

npm audit: Broken by Design

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

2
Designing Design Systems
TkDodo Dominik Dorfmeister 2 votes
4
Introducing RSC Explorer
Dan Abramov 1 votes
6
Fragments Dec 11
Martin Fowler 1 votes
7
Adding Type Hints to my Blog
Daniel Feldroy 1 votes
8
Refactoring English: Month 12
Michael Lynch 1 votes
10