Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don’t recall hearing about constant supply chain attacks with CPAN


That was a different era. The velocity of change is 100x now and the expectation for public libraries to do common things is 100x higher as well.


Perl and CPAN are still a thing, much as people would like to think otherwise.


Because it's never been considered an interesting target, compared to npm's reach?


For a while CPAN was a very big deal and those packages were probably on just about every corporate network on Earth.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: