4 ms·
I am not a fan of the whole javascript craze but for comparison on my desktop machine with I assume average setup of ElementaryOS: $ apt list --installed |
by pi-squared 8y ago
I am not a fan of the whole javascript craze but for comparison on my desktop machine with I assume average setup of ElementaryOS:
$ apt list --installed | wc -l
2394
And on my server the number is 502. Couldn't the same argument be applied here as well? I understand that (probably) users of Ubuntu are more involved than supporting npm packages (or... are they) but it's still a lot of packages to eyeball.
- JoshTriplett 8y agoNot the same thing. Your desktop install might include a few thousand packages total, but that doesn't mean any significant number of packages pull in a thousand dependencies by themselves. Node packages might consist of a single function.
- georgyo 8y agoSure, but the major difference is that those packages are for everything on your system. Dependencies are often added very carefully. In the node case it is not uncommon for a small app to include 50 small packages, and then those packages pulled in 30 unique smaller packages each (on average). Imagine you did an apt upgrade on your system, or decided to install a new package and it said it was going to install 1500 new packages. Would you continue? It would definitely make me pause for a while. But this is the norm in the node world, and people seem to think it is a good idea.
- deleted 8y ago[deleted]
- throwaway5752 8y agoI think that's the point. Outside of very few operating systems and languages with the organization and history supporting them, there's not much that one should trust. Since you can't validate every package yourself, you have to ask yourself if you trust your counterparty. Do you trust ElementaryOS to do have dozens of people validating upstreams before pulling into stable and correctly doing proper package source integrity steps like Red Hat, Canonical, SUSE, et al do? I know they are Ubuntu LTS based but what are the additional packages and how carefully are they curated, built, and stored? May the answer is to not use Node or ElementaryOS depending on how important security is to you. May I'm the weirdo for critically inspecting 3rd party libraries before including them and looking at the transitive dependencies they pull along.
- megous 8y agoThe trust model of linux distro is different from NPM. Dependning on the distro, there may be many maintainers who are separate from upstream developers. These maintainers may manage 5-10 pcakages on average and usually keep tabs on the upstream. There's just no equivalent of maintainers in the NPM land.
- cyphar 8y agoThat is for everything required to run an entire operating system. You're actually putting Node's micro-package madness into even more of a negative light from this comparison -- if it takes only several hundred packages to run an entire distribution, why is it reasonable to require that many packages to run a single web application (not to mention that most distribution packages don't depend on hundreds of others)? The difference is that the only people looking into NPM packages are the Node community. The entire Linux community -- which includes a large portion of the Node community mind you -- looks into the set of packages you are looking at (yes, we've had a bad rap in recent years -- but in our defence we really are trying). I'm a little biased with regards to distributions (I work for SUSE), but I like to think that working on a distribution has given me a much better understanding of how much work goes into those packages. I don't think you could adequately replicate most of that engineering in the time that most micro-package ecosystems have been around.