NPM definitely has its issues and Node itself doesn't really solve for any of this. There is the new Deno project that just launched v2 and has been taking on these types of security issues for a while by requiring permissions like network and filesystem access be explicitly granted. That actually looks pretty promising.
I don't use Deno for much of my work but it's definitely on my roadmap. Between Node.js, Bun, and Deno, there are a lot of great options for JavaScript development right now.
Oh, and did I mention that Deno is written in Rust? *Queues the horns track*
Nostr Boost Stats
- sats
- 20k
- boosts
- 2
- shows
- 2
Boosts Sent
Every boost this booster has sent, as published to Nostr, newest first.
-
-
The Windows kernel issue seems like something that could easily be resolved by Microsoft being required to develop capabilities that you can hook into the Windows kernel from an external vendor point of view and do so in a way that doesn't require any internal kernel manipulation. And the way to prove that out? Microsoft cannot implement any security measures that would be considered competition to other anti-virus or similar products other than through this capability. Then if they want to provide a reasonable security product themselves, they are running through the same loops as any other company would, and this provides a more secure environment for its users.
