upvote
Typescript and the npm/JS ecosystem may be complex, but you don’t need AGI to figure out how to install a CLI built with TS. My agent can figure out how to install this.
reply
Installation is not the problem.

Javascript is plenty fast, but only if it has enough time to JIT the code and can keep it JITed in memory. For long-running backed services, it's plenty fast, for browser things, it's the only option, but for the command line, it adds needless startup time.

Agents make this even worse because they don't have a "sense of time", so if they accidentally do something which causes startup time to increase dramatically, they won't feel it like a human dev would, and won't immediately start optimizing. Unless you have some specific benchmarks in CI that fail any PR which makes the code too slow, agents will just make things slower and slower.

reply
It's not just the complexity. You're also vulnerable to supply chain attacks via NPM. It's also performance as you don't need the entire javascript runtime just for a CLI.
reply
Pretty much every modern language with a package repository is vulnerable to supply chain attacks.

Are there any languages doing something unique or are especially resilient in this respect?

reply
You can get a binary compiled by the author or a trusted source and none of the dependencies can change out from under you. This isn't possible with an interpreted language where the dependencies are resolved (often from dubious places like npm) at install and update time.
reply