I think Python has a better overall philosophy with the batteries included concept. It’s good to have a comprehensive set of libraries which don’t need to rely so much in third party libraries, or where these third-party project solve very specific problems and are well known. Node.js ecosystem, on the other hand, is a huge mess…
I mean bad PR for open source because those issues are happening more and more frequently. And the widespread use of open source means more good and bad actors are posting their codes in GitHub and most of people who use it aren’t aware of all the issues.


































I agree from a technical perspective. For political actors, on the other hand, they use the publicity of these security flaws to smear OSS from executives, policy makers and the general public.
Just FYI, I’ve worked on a big Brazilian state owned company and I heard multiple times from top executives sponsored by politicians of how closed source is better for security because the flaws aren’t apparent, or because only employees of said company could touch the code base. We devs all knew that was all bullshit, but they use this kind of justification to the wide public in order to justify their shady business deals.