• Pup Biru@aussie.zone
      link
      fedilink
      English
      arrow-up
      9
      ·
      1 day ago

      i agree but hate to add the caveat that it (well, typescript) these days is by far the language that i’m most productive in, with the fewest bugs

      it took me a long time to admit that to myself

      it’s still a human rights violation

      • iocase@lemmy.zip
        link
        fedilink
        arrow-up
        7
        ·
        edit-2
        21 hours ago

        It is my GOD given RIGHT to pull half of NPM through MY MACHINE (and get compromised by 500 different MALICIOUS packages) due to my NEED for the MOST up to date PACKAGES!

        I WILL have my hourly update to iseven() or I WILL have DEATH.

        “There’s just no way to prevent these kinds of attacks” says only language where this consistently happens.

        If you ARENT updating your libraries every 15 MINUTES are you even a REAL PROGRAMMER!?

        I MUST get ALL of the latest vulns and exploits on my machine NOW!

        I’ve even written a script to change my API tokens for me since they get STOLEN so OFTEN because my OTHER SCRIPT updates NPM dependencies CONSTANTLY so I can ALWAYS be the FIRST to PULL IN the newest MALWARE.