Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The HTTP imports astound me. Having little control over how bundlers fetch code randomly screams vulnerability vector. How people are okay with it is wild to me.


You're right, of course, but there's little practical difference from doing `npm install` unless you're actually auditing the supply chain. It just automates a step.


The difference is that you have a single file to audit with npm. With Deno, any file in your codebase might pull in a dependency.


Which isn't really a problem for simple one-file 'shell scripts'. For bigger projects, Deno already suggested to maintain all external imports in a central file.


That assumes someone is actually auditing the npm deps.


It’s trivial to audit your dependencies with https://socket.dev

Disclosure: I’m the founder.


Despite the ease of auditing services, there are notoriously a lot of devs using unaudited deps. Maybe they don't even think about it, unfortunately.


They should have at least have something like HTML Subresource Integrity[0], including a hash so at least changes to what comes back from the import hasn't changed.

[0] https://w3c.github.io/webappsec-subresource-integrity


Yes, though it's not enforced when it should be.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: