3 ms·
You'd like Nix. It does just this. Each package declares dependencies on specific versions of other packages. That dependency is expressed as a hash of the inpu
by cwp 10y ago
You'd like Nix. It does just this. Each package declares dependencies on specific versions of other packages. That dependency is expressed as a hash of the inputs to the package, not a semver number. This means that multiple versions of a package can be installed at once, but only copy of each version is installed, unlike npm2.
Security patches are handled by automatically generating new packages that use the patch:
1. Package A relies on Dependency 1, version 1.0.0
2. Dependency 1 is found to have a security problem, so 1.0.1 is issued
3. We generate Package A', which depends on A, but replaces Dep 1 with version 1.0.1
4. Eventually a new version of Package A is released, which depends on Dep 1 at 1.0.1, or maybe a later version
If Package B is introduced with a dependency on the insecure Dependecy 1, only Package B is affected.
IED is at least partially inspired by Nix.