• anyhow2503@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    But why hasn’t JavaScript established a defacto stdlib to replace ask the left pads and is even type packages?

    I’m guessing things were working out pretty alright, even with the insane amount of dependencies per project. The awareness and the increasing frequency of supply chain attacks is relatively recent for npm. But who knows, maybe the tech giants in control of the web standards are happy to keep using their own vendored registries.