3 ms·
I find it offensive and unjustified that author specifically associates "React developers" with "Coders are so used to depending on 3rd party libraries that the
by ivxvm 5y ago
I find it offensive and unjustified that author specifically associates "React developers" with "Coders are so used to depending on 3rd party libraries that they can’t really work without them to the point where some of these libraries even define their career". The problem exists for anybody who uses any library ever, even a C programmer who uses a header only library can get hacked even in a worse way if he blindly updates his library to a new version. Because such a library can have conditionally compiled code that calls system APIs depending on the current OS. Browser is at least sandboxed to some extent. A better and more fair statement would be, that in frontend web development and NPM in particular there are usually too much dependencies and they are blindly updated too often.
- udp 5y agoThe misguided assumption upon which this snobbery is based is that React developers and, say, C developers are different sets of people. Most developers are pragmatic and are probably going to use React or Vue to build a website in 2021 because they’re sensible choices of frameworks, not because they’re necessarily inexperienced.
- pc86 5y agoIt's certainly more prevalent on the front end, though. You'll never see a C/C++ job add looking for "libsodium developer" or "plibsys developer," however front end job postings are littered with "Angular dev" and "React dev" and will not consider anyone who's spent the last decade writing JavaScript but hasn't used whatever front-end button library is in use. I honestly don't know what your system API point has to do with anything when we're talking about a distinct disadvantage to NPM specifically and the JS ecosystem generally.
- ivxvm 5y agoDo you ever see job postings for C or C++ that only require you to know the language? Jobs are looking for domain specific skills, sometimes a framework implies such a domain like "React programmer"="frontend programmer", sometimes it's the other way around like "3d Effects programmer"="GLSL programmer". In all cases though, the bare language is never enough, no matter how many decades you used it, you have to have experience with special tools for your domain, be it frontend, graphics, operating systems, hardware or anything else. Why do you think this is distinct disadvantage to NPM specifically? You can steal someones account and do the same with Rust crate for example, or Go package or even C/C++ header only library. It can get installed or updated to malicious version on user side in the same way, because everyone uses version ranges like "^" or "~" or equivalent. And if you're going to say everyone uses lockfiles, NPM also uses lockfiles for many years already.