3 ms·
> None of them have chosen the "micro-package" way of NPM. This is not something inherent to npm itself, it's what the people using npm choose to publish. No
by m90 7y ago
> None of them have chosen the "micro-package" way of NPM.
This is not something inherent to npm itself, it's what the people using npm choose to publish.
No matter if people like small modules or not, it's not at all related to the topic discussed.
- adev_ 7y ago> No matter if people like small modules or not, it's not at all related to the topic discussed. It is very relevant to the topic discussed. Just for fun : https://npm.anvaka.com/#/view/2d/purescript https://npm.anvaka.com/#/view/2d/purescript > 150 dependencies. Including a package named "one-time", bundled several times in two different versions. To do something highly relevant and technical like "Call a function once". I have no doubt that it is an Highly complex code that requires indeed two packages..... Irony Little question: What would have been the probability of purescript getting malicious if its dependency tree would be something reasonnable... Let's say 20 packages instead of the current ~200 ?
- stephenr 7y agoThank you for linking to that dependency grapher. The crab-grass like dependencies of many/most NPM packages is scary enough, and then they (or you?), I guess because of lazy loading, to improve responsiveness, update it as you watch.. It's like a scene out of an alien monster movie, where the creature keeps growing more limbs.