Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the python counterexample speaks a lot. A lot of languages "hide" their footprint in /usr/local or in a venv somewhere; out of sight, out of mind.

The JVM installs cleanly and is self contained, but any artifacts, by default, are not shared system wide as this _always_ have been seen as a security risk. The hot term for it today is "supply chain attack".

Instead, most Java programs tow their dependencies, giving it a bloated feel because its all just there, present in front of you, stored and running as your own user.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: