5 ms·
> You mean that every time you write a new project you write your own request parser, your own server, your own web framework, your own database access librarie
by xroche 9y ago
> You mean that every time you write a new project you write your own request parser, your own server, your own web framework, your own database access libraries, etc. from scratch?
No, but downloading random code is just insane.
As a comparison, Debian has ~3000 packages, and every single package had an identified maintainer, with its own GPG key, validated in face-to-face meeting with an ID card by three people, an identified upstream, etc. Each maintainer is physically identified, and has passed a number of technical validation steps, explained his motivation etc.
There is also a dedicated security team that can be contacted 24/7.
The system is not perfect, but it provides a good level of security. And this is a project only made by volunteers.
- mrmondo 9y agoDebian security are very good at their job indeed, however so many of the packages are so old they’re not usable, furthermore Debian doesn’t enable SELinux by default and has a number of policies missing which significantly weakens the average deployment.
- cassowary 9y agoThose comments are all irrelevant to the OP's point. Debian software is "old" by intention; it is part of the spec that it shouldn't be a moving target. As for Debian making some policy decisions that you disagree with, it's very different for Debian to make decisions than for NPM to make decisions. There's just no comparison.
- jacalata 9y agoI agree that Debian is so different to npm as to make any comparison irrelevant, but you should direct that at the comment which introduced the comparisons, not one that pointed out ways it doesn't work to compare them.
- mrmondo 9y agoIndeed, sorry if I didn’t make it clear - I was commenting on the previous person who talked about Debian - not the OP.
- onion2k 9y agoDebian has ~3000 packages, and every single package had an identified maintainer... As of yesterday npmjs had 516,132 packages, which was an increase of 373 since the day before. Debian's 3000 packages is a couple of weeks of npmjs activity. Even if you stripped out the unnecessary, abandoned, or duplicate packages you're still looking at a something significantly different to Debian. For what it's worth I think a well-maintained, verified, and known secure subset of npmjs would be a great idea, but the logistics of providing that would be effectively impossible without some serious cash behind it.
- mafro 9y agoFWIW I have always thought this would become a problem for nodejs. Encouraging one-liner packages [1][2] is a recipe for an enormous dependency tree, and a totally impossible-to-manage security situation. Python projects I have recently worked on might max out at 50 packages. The last project I worked on with nodejs as front end had 3000+ packages just for the UI. [1] https://github.com/sindresorhus/ama/issues/10#issuecomment-117766328 https://github.com/sindresorhus/ama/issues/10#issuecomment-1... [2] https://github.com/kevva/is-positive https://github.com/kevva/is-positive
- gjjrfcbugxbhf 9y agoDebian packages on average have more functionality than npm packages. Such a subset as you describe would be one (or a few) Debian package(s).
- seanp2k2 9y agoThe culture around what should be in a package is vastly different. Node has left-pad. Debian has stuff like Apache. Sure, those are radical examples, but the barrier to entry for Debian is pretty high (as is the standard for quality) vs npm where anyone can put whatever out there. How do things like left-pad even come to be widespread dependencies? Does the node development process involve a lot of "gee I wonder if someone made a package for (simple thing I need to do with a few lines of code)"?
- ubernostrum 9y ago
- jlgaddis 9y ago> ... Debian has ~3000 packages ... It's irrelevant to your point but Debian 9 included >51,000 packages [0]. [0]: https://www.debian.org/News/2017/20170617 https://www.debian.org/News/2017/20170617