The Most Useless NPM Repos
カートのアイテムが多すぎます
カートに追加できませんでした。
ウィッシュリストに追加できませんでした。
ほしい物リストの削除に失敗しました。
ポッドキャストのフォローに失敗しました
ポッドキャストのフォロー解除に失敗しました
-
ナレーター:
-
著者:
TIL: npm has a package called "none." It does exactly what it sounds like: nothing. It still gets 300 downloads a week. There's also "is-even," which calls out to an AI model to check whether a number is even, with about 80% accuracy, because apparently modulo operators were too much work. Matt Triner sits down with Matt D'vertola, Greg Vanore, and Jeff Segal to laugh at npm's most absurd packages and then get serious about what they expose: arbitrary code execution on install, a transitive dependency system that snowballs trust across thousands of hands, and why typosquatting a familiar package name still works embarrassingly well. The jokes are the hook. The supply chain risk is the point.
Episode Chapters:
00:00 Introduction to NPM and Its Impact
06:45 The Dark Side of NPM: Security Risks
11:49 Micro Packages: A Double-Edged Sword
14:45 Cultural Reflections on Node.js and NPM
19:41 The Evolution of UI and UX Development
24:24 Cultural Divide in Application Development
28:47 The Rise of JavaScript and Node.js
33:47 The Importance of Software Engineering Fundamentals
35:30 Best Practices for NPM Security