@darius @roadriverrail You're correct that any language ecosystem is vulnerable to this. NPM seems to be more vulnerable due to the vast number of dependencies, which is a direct consequence of the dev community deciding that every oneliner requires its own package.
@ieure @darius @roadriverrail I still don't know why people evangelise node. It's not worse than many other things but even in the best light its not _better_