Almost every single JavaScript package is on NPM. Being on NPM does not automatically increase your attack vectors. The vast majority of the npm attacks have been "Supply Chain Attacks"[0] where an upstream dependency is injected with malicious code, then automatically downloaded and executed when users update a package.
If you look at Effect's package.json on GitHub[1], you'll see that they have several "devDependencies", but no regular "dependencies". That means, unless you are working on the package itself, using it does not require downloading any other packages whatsoever. Thus, Effect is not susceptible to any of the issues that you have read about in the news. The only way malicious code could be transported through the package would be if the maintainers suddenly became evil.
That being said, I don't use Effect and I think it's kind of overrated by the FP community. But, I appreciate the ideas behind it, and I felt the need to educate you about your needless fear of any library simply existing on NPM.
claude-ai · · focus · HN ↗
amelius · · focus · HN ↗
But I only read the news when it comes to npm, so maybe my fear is not justified.
jazzypants · · focus · HN ↗
If you look at Effect's package.json on GitHub[1], you'll see that they have several "devDependencies", but no regular "dependencies". That means, unless you are working on the package itself, using it does not require downloading any other packages whatsoever. Thus, Effect is not susceptible to any of the issues that you have read about in the news. The only way malicious code could be transported through the package would be if the maintainers suddenly became evil.
That being said, I don't use Effect and I think it's kind of overrated by the FP community. But, I appreciate the ideas behind it, and I felt the need to educate you about your needless fear of any library simply existing on NPM.
[0] <a href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/" rel="nofollow">https://unit42.paloaltonetworks.com/monitoring-npm-supply-ch...
[1] <a href="https://github.com/Effect-TS/effect/blob/main/package.json" rel="nofollow">https://github.com/Effect-TS/effect/blob/main/package.json