← Back to context

Comment by user3939382

2 months ago

I don’t recall hearing about constant supply chain attacks with CPAN

That was a different era. The velocity of change is 100x now and the expectation for public libraries to do common things is 100x higher as well.

Because it's never been considered an interesting target, compared to npm's reach?

  • For a while CPAN was a very big deal and those packages were probably on just about every corporate network on Earth.