3 ms·
The CPAN ecosystem provides some basic guarantees that I haven't seen mentioned for other language's repositories. For example every distribution uploaded to th
by perigrin 16y ago
The CPAN ecosystem provides some basic guarantees that I haven't seen mentioned for other language's repositories. For example every distribution uploaded to the CPAN is tested on some subset of (using last month's statistics[1]) 15 different operating systems, across 81 platforms, and 26 different versions of Perl. Not every package is tested on every perl and every platform because this is a volunteer effort, but the major platforms (Linux, Windows, BSD, Solaris) are generally covered. These test results are aggregated and reported on search.cpan.org.
Every package uploaded is given a Bug Queue (rt.cpan.org) so bugs and patches can be reported to the author. Additionally distributions can now specify in their metadata (META.yaml/META.json) the source code repository for the code so you can see from search.cpan.org the place to get the latest code to patch against. Additionally there is a process that if a maintainer goes rogue and stops responding, packages can be taken over. This doesn't happen often but has been used when other options fail. Many modern projects have several co-maintainers who can all make releases lowering the "bus factor".
Right now the biggest problem is finding the wheat for all the chaff. Sturgeon's Law applies, 90% of everything is crap. With 21038 (as of this writing) unique distributions, finding the ones that are well written, useful, and generally "best" is actually a difficult problem. You're not alone in finding that hard, but there are projects like Task::Kensho[2] to curate CPAN. This process is hard and would require a full time team of experts to perform properly.
It is big problem but one I think I'd rather have than when I was (for example) working in Java in 2005 and not only had to go through the effort of assessing the module in question (will this work? is it good? will I have problems later) but also had to hunt around the web for where all the different projects were located.
[1]: http://stats.cpantesters.org/ http://stats.cpantesters.org/
[2]: Full disclosure, Task::Kensho is a project I started in 2007 based upon the feedback of several people in the Perl community.