4 ms·
So, a few answers. A) most of the dependencies that Faker has are common with lots of JS projects that I work/have worked on in the last few years. Looking at
by trowawee 5y ago
So, a few answers.
A) most of the dependencies that Faker has are common with lots of JS projects that I work/have worked on in the last few years. Looking at that dep list[0], I'm familiar with most of them. They're mostly common packages. To some degree, I'm relying on the thousand eyes here.
B) In terms of security risk, Faker runs in test suites to generate data and locally on dev machines, sometimes, to populate sample DBs. It lives and runs in managed environments and doesn't get packaged into prod anywhere. The risk profile isn't nonexistent, but it's also not a massive risk.
C) I really think we're underrating the amount of work that would required to recreate this project (not uncommon here). Faker can spit out 205 different types of random data in 46 different languages/dialects. Building that is not a two day project (evidenced in the fact that people have been working on this for years now); making sure you can generate all that data correctly in all those different languages is a non-trivial task; building and maintaining it internally will take dev time and energy and will continue to require that time and energy on an ongoing basis.
You're talking about this choice here and in other comments with an air of "silly JS devs, just build this easy thing!". I don't know if it's your intention, but you're coming off dismissive and ignorant. People think about these tradeoffs all the time, and sometimes decide to use packages like this. I think it might behoove you, if you find someone's decision confusing, to start from the position that they are also reasonably competent professionals and see if you can understand why a competent professional might make a different decision than the one that seems obvious to you, rather than assuming that if someone makes a different decision they're stupid and/or incompetent.
[0]: https://github.com/faker-js/faker/blob/main/package.json https://github.com/faker-js/faker/blob/main/package.json