Sébastien Cevey Profile picture
Software engineer at DeepMind, amongst other things obviously. Previously at Google & the Guardian.
Dec 2, 2018 13 tweets 3 min read
A few thoughts on the Node event-stream compromise:
[context: theregister.co.uk/2018/11/26/npm…]

Discussions seem to be overly focused on Dominic's role/responsibility, or the reliance on unpaid open source contributions, when the root is clearly a systemic issue with the Node ecosystem. The nature of NPM is such that I'd expect most large corporate Node software to depend on at least a couple of single individuals' hobby projects. The problem is that those projects don't tend to fulfill the same expectations of security, quality and maintenance.