5 ms·
This is why regression suites are important. EDIT: I wasn't dissing the developers. They have regression, this was just an accident. I was stating it is import
by 0xff00ffee 6y ago
This is why regression suites are important.
EDIT: I wasn't dissing the developers. They have regression, this was just an accident. I was stating it is important. My bad (too late to delete).
- SSchick 6y agoThe package does have CI setup, however the test matrix does not cover the latest node versions (which are the ones that are affected). See https://github.com/then/is-promise/blob/master/.travis.yml https://github.com/then/is-promise/blob/master/.travis.yml (missing v11, v12, v13, v14)
- RyJones 6y agoAnd CI is failing[0]. [0]: https://travis-ci.org/github/then/is-promise/builds https://travis-ci.org/github/then/is-promise/builds
- SSchick 6y agoThe failing CI here is unrelated to the issue but it's still pretty bad a release was made with failing CI.
- jessaustin 6y agoIt was a five-year release (followed quickly by a 3.5-hour release and a sub-minute release) [0], so they may not have wanted to dig into CI. [0] https://github.com/then/is-promise/releases https://github.com/then/is-promise/releases
- seibelj 6y agoInstall any moderately complex nodejs lib or app and it will throw tons of warnings, ignored errors, and security issue alerts. As you should with any app running in production, lock down everything and watch network traffic because there are innumerable backdoors in the JavaScript ecosystem.
- 0xff00ffee 6y agoMy company's current production electron app has 360 npm dependencies. We have CI for the UI but not for the USB/FFI stack, so any time we have to touch that code everyone blanches. > innumerable backdoors in the JavaScript ecosystem. Same goes for Python and CPAN. Any "click here for fancy module" installer has this problem.
- enitihas 6y agoYou don't need so many dependencies with python. Python is a batteries included language, and so are most python libraries.
- 0xff00ffee 6y agoI fully disagree. Open up any serious Python project and you'll find significant dependencies. Math, graphics, IO, stats, ML... anything you really want to do requires dependencies. In fact, one of my biggest issues with Python is the cross-platform incompatibility of many packages which makes it a terrible choice for my deployment. (Even worse if the project has Cython components!) I often end up having to scour github for forked pywheels that aren't vetted. Which are then cloned ad infinitum. Its a tradeoff between extensibility and open source / free software, and robustness.
- enitihas 6y agoMath -> You use numpy, scipy, none of these have any significant dependencies. And libraries this complex are not even available for node. Graphics -> Python comes with included Tkinter, and others are also one include away. Stats -> Scipy does a lot of the stuff. There is a built in package for stats. Again, no stats package has 100 dependencies, and node doesn't even have anything with even 1/10th of the features ML -> I mean node has nothing here, nothing, while pytorch has total of six dependencies. In node, left pad might have these many. Python doesn't need left pad, isNumber, isInteger, isOdd, isPromise , take your pic. > In fact, one of my biggest issues with Python is the cross-platform incompatibility of many packages which makes it a terrible choice for my deployment. (Even worse if the project has Cython components!) But python has high performance libraries written in C, can you even use node for any of the cases where python has platform compat issues? It is a tradeoff, and there is no comparison. Python needs far far less dependencies than node. e.g, Flask has 2 total dependencies, express has 48 direct dependencies, and even then flask comes out ahead on features, so much so that you would need many more packages to do the same stuff with express.
- nemetroid 6y agoCould create-react-app have avoided this through regression suites?
- 0xff00ffee 6y agoBumping your comment because I would like to know. I'm following the github thread.
- jakear 6y agoPotentially. If cra had pinned all their deps, and used a bot to automatically bump deps contingent on passing a comprehensive regression matrix, this would have been avoided. GitHub's Dependabot is good for this. In my opinion everybody besides libraries should pin deps and use dependabot.
- gombosg 6y agoExactly. We use Renovatebot for the same purpose. It pins dependencies and creates PRs for updates. Amazing to see how often the builds break, even sometimes after minor updates. But at least we fix them before release, and not after... :)
- jakear 6y agoYep. One of the very nice things about npm/node versus python or go or some others is that package locks and dependency pinning is possible. But few people seem to use it. I’ve seen reports of people using a go library that gets a minor update and breaks their app, at which point they become SOL as go always installs the lad test version. I myself have been working in python projects where the dockerfile simply says “pip install blah” and I get different deps than the working version. No clue why anyone would be okay with working like that.
- jen20 6y agoIt's not true that Go always installs the latest version of a dependency. `go get github.com/x/y@v1.3.4` installs v1.3.4 of x/y, assuming there is a tag matching that.