4 ms·
Wouldn’t the alternative simply be bigger libraries grouped around common functionality or extension points? Like jQuery or similar (only an example, not sure w
by e_proxus 6y ago
Wouldn’t the alternative simply be bigger libraries grouped around common functionality or extension points? Like jQuery or similar (only an example, not sure what is hip today).
I’d rather trust a fairly big library with an organized open source group behind it than thousands of small libraries by unknown developers.
- toxik 6y agoThe NaN library is literally just testing if the value is a number with typeof v === 'number' then tests if v !== v. This is not something you need a library for at all, big or small.
- e_proxus 6y agoYeah, this is my philosophy when developing Erlang software as well (also seems to be shared by most of that community). A few dependencies less are always worth a few functions more.
- rodinia 6y agofwiw, I've been doing professional JS (mostly server, good amount of client) for about 5 years now and have never pulled in a single function package before as a direct dependency. Every team I've been on has used Lodash or Underscore in the capacity you describe. https://lodash.com/docs/4.17.15 https://lodash.com/docs/4.17.15 https://underscorejs.org/ https://underscorejs.org/
- hyperbovine 6y agoI agree that this is the sane alternative, but sanity does not seem to be winning out. Our friend number-is-nan, for example, has 12 million downloads a week. A week!
- stephenr 6y agoIt’s like someone saw how much the is-odd/is-even (yes one of those first two depends on the other and just returns the inverse with !) packages are downloaded per week and said “hold my beer” Of course they don’t hold a candle to “is-number” which has 29M/week Of course this is completely unrepresentative of reality because “yolo just install dependencies at deployment” may mean it’s downloaded 5 or 10 or 50 times for a high traffic site/service with a bunch of backend installations.
- SamuelAdams 6y agoAnother good example: .NET Core. I trust that Microsoft hires good people who can update the core libraries in .NET Core to not do dumb and unexpected things. I trust Microsoft to have controls that check for malicious behavior and prevent / fix that quickly. I trust Microsoft to vet all open-source dependencies they decide to integrate into their products. Also the legal team likes this a lot more too. If a data leak occurs due to some library that Microsoft wrote, we have one company to sue. If it's a react package, who the hell do we go after? Most of these are "at will" / MIT license style things, so we are more or less SOL anyways, but legal teams don't like hearing that. You also get at a more fundamental question. What is trust? Why can we trust a larger organization over a collection of individuals? Are they not the same thing? What social structures make one more trustworthy over another? There's a great book on this by Bruce Schneier called Liars and Outliers. I highly recommend you read it. https://www.schneier.com/books/liars_and_outliers/ https://www.schneier.com/books/liars_and_outliers/