4 ms·
Unpublish isn't that bad. He could have just as easily made patch updates to each of his modules with malicious install scripts and/or malicious runtime behavio
by esailija 11y ago
Unpublish isn't that bad. He could have just as easily made patch updates to each of his modules with malicious install scripts and/or malicious runtime behavior.
Depending on 200 tiny modules, you have 200 different risks vs just having 1 risk.
- nailer 11y ago> Depending on 200 tiny modules, you have 200 different risks vs just having 1 risk. vs the risk of rewriting common, well tested code 200 times.
- dozzie 11y agoLike checking if the thing at hand is an array? Or a positive integer? Or iterating through hash's keys? Or another implementation of reduce()/fold()? Why won't you outsource your condition checking to a well-tested wrapper around if-else?
- nailer 11y ago> Like checking if the thing at hand is an array? Yes. ES6 has isArray(). Use a well known polyfill rather than write your own for ES5 environments. > Or a positive integer? Yes. As discussed there are edge cases around negative 0 that you may not think of. > Or iterating through hash's keys? Personally, yes, but not necessarily. There's 'for of' which iterates over an Object's own keys - I'm presuming you know regular 'for in' iteration iterates over parent prototype keys and why that's often unwanted - but 'for of' is relatively new. I prefer an approach more consistent with how arrays are handled, so I use Object.prototype.[someprefix]forEach() and share the code. > Why won't you outsource... Using libraries isn't outsourcing. Please read https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- nilliams 11y agoThat 'just as easily' does not cause problems for us cautious devs who pin dependencies with 'npm shrinkwrap' and review changes to our dependencies. Unpublish was an actual problem, and that problem has been fixed.