3 ms·
NPM specially assumes that "patch versions are safer to update than minor or major version". MVS doesn't make that assumption. > it seems to stem from bad desi
by nicksnyder 8y ago
NPM specially assumes that "patch versions are safer to update than minor or major version". MVS doesn't make that assumption.
> it seems to stem from bad design decisions made by NPM authors
Yep.
> doesn't have a lot to do with Minimal Version Selection
The pain I experienced has nothing to do with MVS (because npm doesn't use MVS). The observation of the post is that my pain would not have happened with MVS. No more, no less.
- felixfbecker 8y ago> NPM specially assumes that "patch versions are safer to update than minor or major version". I don't see where that assumption is baked into npm - the creator of a package declares the dependency constraints, so they are the ones making the choice which versions can be trusted well to work. You could pin all dependencies but then users would need to download tons of duplicate dependencies because of slight version differences everywhere. So it's a tradeoff, but the user makes it, not npm.
- nicksnyder 8y agoRephrased: npm’s design incentivizes projects to assume “patch versions are safer to update than minor versions are safer to update than major versions” to avoid dependency duplication. Such incentives do not exist with MVS because all that is required is a total ordering and there is no duplication within a major version of a module.