3 ms·
The npm ecosystem needs something like the distinction between Ubuntu's "main" and "universe" repositories, so that you have a smaller subset of known-good pack
by segphault 6y ago
The npm ecosystem needs something like the distinction between Ubuntu's "main" and "universe" repositories, so that you have a smaller subset of known-good packages with harmonized transitive dependencies, stronger centralized curation, a lot more direct scrutiny, tighter control over versioning, and some party that is responsible for addressing vulnerabilities and ensuring appropriate maintainership.
As a venture-backed startup, the company behind npm needed the number of packages and the number of downloads to constantly trend upward in order to justify their valuation. This led to extremely poor policy and prevented them from taking strong steps to remedy the deterioration of the ecosystem. Now that it's owned by Microsoft, there's an opportunity to fix this.
Linux distributions have decades of experience solving these problems, there's no excuse for the JavaScript community to continue ignoring the longstanding precedents and best practices that have emerged from that experience.
- mayank 6y agoThis is a really good idea, and a fitting analogy. NPM already supports private registries, so it would be a simple configuration change to point to "main". On top of that, there is a lot of good work in the node community around static analysis, CVE detection in transitive dependencies, and more finely grained security perimeters, which could be used to detect possible backdoors or malicious code.
- jessaustin 6y agoIt would be completely straightforward to do the work you describe. Presumably numerous private actors have already done it for themselves. Until someone does this work and shares it with the public, we'll all have to wonder how valuable it would really be... anyway, it's unreasonable to expect the npm people to do this work on top of everything else they do.
- rgbrgb 6y agoAnother example where this has worked really well is Rails... I think originally there was opposition to this type of Big Framework approach in the node community, but personally I don't want to pick and compose a bunch of packages from NPM and would rather spend time on higher order customer problems than simple technical ones e.g. getting a next.js app to send emails.
- DLA 6y agoLove this idea, a lot! The quality, security, support, code review, etc. bar for “main” could indeed help. Maybe there’s an additional measure - what’s the size and complexity of the deps tree. Higher “score” for more shallow/narrow trees.