• Pup Biru@aussie.zone
    link
    fedilink
    English
    arrow-up
    9
    ·
    20 hours ago

    i agree but hate to add the caveat that it (well, typescript) these days is by far the language that i’m most productive in, with the fewest bugs

    it took me a long time to admit that to myself

    it’s still a human rights violation

    • iocase@lemmy.zip
      link
      fedilink
      arrow-up
      7
      ·
      edit-2
      13 hours ago

      It is my GOD given RIGHT to pull half of NPM through MY MACHINE (and get compromised by 500 different MALICIOUS packages) due to my NEED for the MOST up to date PACKAGES!

      I WILL have my hourly update to iseven() or I WILL have DEATH.

      “There’s just no way to prevent these kinds of attacks” says only language where this consistently happens.

      If you ARENT updating your libraries every 15 MINUTES are you even a REAL PROGRAMMER!?

      I MUST get ALL of the latest vulns and exploits on my machine NOW!

      I’ve even written a script to change my API tokens for me since they get STOLEN so OFTEN because my OTHER SCRIPT updates NPM dependencies CONSTANTLY so I can ALWAYS be the FIRST to PULL IN the newest MALWARE.