3 ms·
> The issue of having a thin library is that one then ends like the relationship POSIX has with ISO C. It should be noted that the vast majority of participant
by fivea 5y ago
> The issue of having a thin library is that one then ends like the relationship POSIX has with ISO C.
It should be noted that the vast majority of participants on that thread do advocate against bloating Rusty's stdlib, and they point out a very thorough and convincing list of prior experiences from other programming languages that justifies this stance.
It's as if they learned from other people's mistakes and bad experiences.
- pjmlp 5y agoI know, yet from my point of view that is a mistake, they think they learned, yet the npm attack of today proves otherwise.
- spoiler 5y agoNpm is the biggest and most active developer ecosystem out there. Statistically, mistakes/issues are going to happen. Given its popularity, it's easy to talk shit about npm, but rarely do people say anything actionable. C++/boost could have a bad actor upload malicious code. The only difference is that people probably wouldn't notice for months, because everyone's running decades old versions of boost anyway. Not because they're mindful of security, but because nobody can bother to update it unless the need becomes dire. Now, a favourite of mine (often preached by CPP Deva): if you're a good enough developer, you don't have these problems. Were the npm problems avoidable? Yeah, if "yOu aRe a GoOd eNoUgH dEvElOpEr" and use lock files (generated by default) and only install from it (eg `npm ci` being the simplest method). Disclaimer: I used to be an everyday npm user, and I'm not a fan of it by any metric, but the npm shit-slinging edgyness hype is so last year's trend. Jesus Christ.
- fivea 5y ago>>C++/boost could have a bad actor upload malicious code. The only difference is that people probably wouldn't notice for months, because everyone's running decades old versions of boost anyway. Not because they're mindful of security, but because nobody can bother to update it unless the need becomes dire. This baseless assertion is quite wrong and completely detached from reality. Boost is not a one-man show which is a git commit away from disaster. Boost is a commmunity-driven project where any change to an existing package is subjected to a public review and proposals for new components are performed through a submission process. https://www.boost.org/users/faq.html https://www.boost.org/users/faq.html
- spoiler 5y agoI write C++ (for better or worse), and I know Boost is an algamation of libraries and many hard working maintainers. I didn't mean to imply anything bad about boost. I think you misunderstood me because I gave a poor example. I'm talking about the general/average mindset of the C++ community when it comes to updating dependencies. Also the way dependencies are "managed" (or lack of it) in virtually every project. The HN crowd isn't considered "average" in that dimension, probably. So even if you yourself have a culture of keeping things updated with Conan or whatever, it's definitely not the status quo.
- fivea 5y ago> yet the npm attack of today proves otherwise. If you're referring to the colors package in NPM, that is not an attack at all nor did it proved what you think it proved. If anything, the colors package episode just showed that there are companies mindlessly ingesting dependencies without a shred of due diligence.
- pjmlp 5y agoAnd crates.io prevents similar action how exactly?
- fivea 5y ago> And crates.io prevents similar action how exactly? You're confusing a service where anyone can distribute their half-assed package with the dependencies you adopt for your package. It's not the job of crates.io nor npm to vend dependencies. That job is on you and on anyone who wants to consume a third-party package. It's weird how some people complain that they are not obligated to perform any form of due diligence at all on basic things like be responsible for the crap they decide to mix with their work. I mean, the protest release of the colors package was done with a very obvious and very glaring major version bump, and people just swallowed it whole without any check at all? That's a problem of your own making, not npm or crates.io.
- pjmlp 5y agoThat is a culture problem that those ecosystems create, by driving everyone to depend on function sized packages even for stuff that should be part of the standard library from day one, e.g. error.