3 ms·
I respectfully disagree if you have some other things to do in your free time than maintaining dependencies, trying to figure out why your project won't compile
by mickaelkerjean 5y ago
I respectfully disagree if you have some other things to do in your free time than maintaining dependencies, trying to figure out why your project won't compile at all in 6 months of time while reporting 100 security issues, what will be the next change in webpack to will require to update both your config and some plugins, why does npm now cry for you to use a "--legacy-peer-deps" flags to nicely handle dependencies you didn't know you had while being happy you can't compile your frontend project on a small raspberry pi. It's not because you can use all those tools than you should
- bstar77 5y agoYou are literally criticising Webpack for its best features. Identifying outdated libraries and potentially dangerous vulnerabilities is a huge plus for Webpack. Do you think just because you include a CDN lib in the global space vulnerabilities just magically go away? You also don't need to include packages that are poorly engineered and maintained. For what you do decide to use, you are getting visibility into the warts that you may have blissfully ignored in the past. The issues you are describing are not really problems anymore unless you let your app get woefully out of date. The web and browsers are a moving target, so it's critical that you minimize running legacy code wherever possible. Npm/Yarn and Webpack is a huge step in making that manageable. jQuery has been on autopilot for years because it has limited usefulness. We've collectively moved on except for a few holdouts.
- gunapologist99 5y agoYou are literally criticizing jQuery for its best features. Not having outdated libraries and potentially dangerous vulnerabilities is a huge plus for jQuery. Do you think just because you use a build tool for modules from all over the npm-verse that vulnerabilities just magically go away?
- bstar77 5y agojQuery has had its share of dangerous vulnerabilities. https://snyk.io/vuln/npm:jquery https://snyk.io/vuln/npm:jquery
- gunapologist99 5y agoagreed, but it's only one library, and might be the only one you need; really, it has an excellent track record considering that it's been around longer than npm itself.