3 ms·
A safer way in my opinion is to: 0. read module license 1. checkout the module to be patched 2. modify it 3. do "npm pack" to save a tarball 4. set the dep
by partycoder 9y ago
A safer way in my opinion is to:
0. read module license
1. checkout the module to be patched
2. modify it
3. do "npm pack" to save a tarball
4. set the dependency version in your package.json to the tarball. and make sure to the tarball is available during build time.
5. report the issue in their issue tracker for long term fix.
In contrast:
with this "quick fix", the dependency can change, or the transient dependencies can change. This would cause the quickfix patch to not apply anymore.
The only way to guarantee that it won't break is to save the module and all its dependencies. Something that is equivalent to npm pack.
Finally... don't get yourself into a licensing problem. Take a good look at the license before modifying a project.
- charlesetc 9y agoDoes npm even allow you to use projects that don't allow you to make changes to their code?
- jogjayr 9y agoAs in it checks the license in the source repo and prevents installation of dependencies with licenses that prohibit source modification?
- partycoder 9y agoYou can have an npm module with any arbitrary licensing. https://docs.npmjs.com/files/package.json#license https://docs.npmjs.com/files/package.json#license
- drostie 9y agoNo because how the hell would they know? I author a module for my employer and describe it with their developers@ email and as UNLICENSED; how does NPM discover that I am legally authorized to use and modify this package?