Hi @alien4u! That's a fair question, and you're right that the Node/npm ecosystem comes with its own supply-chain considerations.
The decision is less about Java itself and more about consolidating our developer tooling around a single CLI that we can evolve going forward. Maintaining two implementations means duplicating feature development, fixes, testing, security updates, and compatibility work.
Consolidating on the Node.js CLI lets us focus that investment on one developer experience, while also aligning more closely with the JavaScript/TypeScript ecosystem where many SuiteCloud developers already work.
So the main benefit isn't that Node is inherently better or more secure than Java, it's being able to invest more deeply and consistently in a single CLI.