7 ms·
Dependencies of your dependencies! Imagine installing a library that depends on a couple dozen libraries in its own right. You may not have time to inspect ever
by creatornator 7y ago
Dependencies of your dependencies! Imagine installing a library that depends on a couple dozen libraries in its own right. You may not have time to inspect every single node in the dependency graph.
- saagarjha 7y agoIt's going to sound uncharitable, but if you're clearly being rejected for something that your dependencies is doing wrong you should make time to figure out which one it is.
- Fr0styMatt88 7y agoIs it really difficult to find private API usage? Can they be searched for through static or dynamic analysis? I don’t develop for iOS so I’m genuinely curious. Do they provide automated tools for developers to use? Or a flag that fails your build if you’re trying to call private APIs: For that matter, how are the reviewers catching these API usages? I find it strange that a private API can be used accidentally, without something notifying the developer before they’ve gotten to the stage of submitting their app.
- saagarjha 7y ago> I find it strange that a private API can be used accidentally, without something notifying the developer before they’ve gotten to the stage of submitting their app. It's difficult to use private API accidentally. However, it is possible to use a dependency that purposefully uses private API, which is what happened here. > Do they provide automated tools for developers to use? No. > Or a flag that fails your build if you’re trying to call private APIs Kinda, but that doesn't help you if your dependency is trying really hard to use that API and has been precompiled. > For that matter, how are the reviewers catching these API usages? They're running somewhat stupid static analysis and possibly some dynamic analysis? They don't tell you what they do but they're not very good at it and don't generally catch even basic obfuscation. However, if a human finds your private API usage and you look like you're trying to obfuscate it, they won't be nearly as lenient.
- aaronbrager 7y agoYes, as indicated in the OP you can use otool to see which private APIs are being called.
- abjKT26nO8 7y agoYour dependencies (including the transitive ones) are your responsibility. If you can't keep track of them, perhaps you fucked up. https://queue.acm.org/detail.cfm?id=3344149 https://queue.acm.org/detail.cfm?id=3344149
- geofft 7y agoAs an end user, can I just say how uncomfortable I am at the idea that some app on the App Store includes some node.js dependency where the app developer has no idea what's in it? What if it's event-stream? If you're sending me code to run on my computer—especially if I'm paying for it—you either need to have glanced at the code yourself or have some reason to trust what's in there (it's from a company you have a business relationship with, it's a major library from a known author that other apps on the store are also using, etc.). Otherwise you're being irresponsible. If you don't have the time to look at the library, don't use it.
- tracker1 7y agoSo never run Linux?
- rmgraham 7y agoOr only run Linux? * * (any source available OS)
- tracker1 7y agoGP says not to run anything you haven't looked at yourself for the most part, paraphrasing. I doubt anyone has self audited all the software and drivers going into a desktop Linux distro. The point is, at some point you stop digging
- de_watcher 7y agoDesktop Linux distros have package maintainers and companies behind them like RedHat or Canonical.
- toast0 7y agoGP says not to publish anything you haven't looked at (or OKed by appeal to authority). Publishing should be a higher standard than running.
- geofft 7y ago
- Scapeghost 7y ago> Dependencies of your dependencies! Imagine installing a library that depends on a couple dozen libraries in its own right. You may not have time to inspect every single node in the dependency graph. Excuse me, are you, the developer, telling me, a user, that you don't know what you're giving me to run on my computer?
- michaelmrose 7y agoHi my name is node_modules have you met me? If you invite me to a party I bring my 500 closest friends as my plus one! I just looked at the node_modules folder for a project that runs user configured code when your imap server gets a new mail via imap idle. It's called imapnotify and inside its node_modules dir I see it pulls in 549 js files. The majority are under 100 lines per file dozens are between 1 and 30. Cutting just the last segment so that /foo/bar/baz.js and /bam/baz.js both appear as baz.js and removing dupes reduced the number of unique filenames to 383. Basically every js dev is either telling you or not telling you that they don't know what they are giving you to run on your computer.
- catalogia 7y agoThere are reasons forums known for being less diplomatic than HN often take delight in heaping scorn and ridicule on js devs. This is one of those reasons.
- JohnFen 7y ago> If you invite me to a party I bring my 500 closest friends as my plus one! That sort of thing is a big red flag that perhaps you should reconsider using that package. But even if you do use it, that in no way reduces the fact that it's your responsibility to know what you're shipping.
- michaelmrose 7y agoThat is every javascript package ever incidentally. Do you have an alternative suggestion as far as connecting to an imap server and responding to events? Not a library to write such a thing but an actual implementation.
- JohnFen 7y ago> You may not have time to inspect every single node in the dependency graph. You may not have time to do your job properly? If you're using libraries in your project, it's normal and expected that you know what those libraries are doing and what those libraries depend on. You should know this stuff regardless of what Apple (or anyone else) may require.