4 ms·
I wish some of these large projects would start seriously auditing their dependencies and stop pulling in dependencies that have many dependencies themselves. T
by moojd 5y ago
I wish some of these large projects would start seriously auditing their dependencies and stop pulling in dependencies that have many dependencies themselves. There is a one-two punch of a culture of "there's a package for that" and npm not requiring flat dependency trees by default. The denial in the node community that npm is uniquely bad is frustrating. I want the community to stop denying and own these issues so things can get better. It's going to take the authors of large packages to start evangelizing the use of fewer, higher quality packages, using flat dependency trees, and re-implementing trivial functions instead of adding another node to trust.
- ratww 5y agoIt is an uphill battle, lemme tell you. There is a bit of a culture clash inside Javascript. Even when you're a veteran contributor, sometimes maintainers resist changing packages, as simple as they are, because there is an implicit assumption that popular packages, or even packages with too many dependencies are "better" or "handled all the edge cases". Even with careful evaluation of the options and a write-down of issues and a proper comparison, you need ten times as much energy to remove a package than it took to add it. It's even worse is when "too many packages" is in the DNA of the package you're collaborating.
- phist_mcgee 5y agoDon't forget too that npm by default allows minor version upgrades with the ^ prefix for version numbers, which means that unless you properly lock your dependencies, you can reintroduce changes over time, just by running npm install.