4 ms·
Direct link to the rendered docs for this feature: https://github.com/bmeck/node/blob/ceadb473e6d3a22f38b737108fb5ac943bf8be09/doc/api/esm.md#https-and-http-imp
by mstade 5y ago
Direct link to the rendered docs for this feature: https://github.com/bmeck/node/blob/ceadb473e6d3a22f38b737108fb5ac943bf8be09/doc/api/esm.md#https-and-http-imports https://github.com/bmeck/node/blob/ceadb473e6d3a22f38b737108...
It's unfortunate I think that the docs don't mention integrity checks or caching, but those things are mentioned in the PR thread. Integrity via policies which seems to be a new feature as well[1], perhaps designed to essentially obsolete things like package-lock.json et al? Caching is punted till later, presumably to not hold up progress on this particular feature.
Seems to me these are actually steps in the right direction, paving some of the cow paths already created by npm and yarn. I for one would love to see package-lock.json etc make way for policies. Security is a concern for sure if there's no integrity checking on the packages loaded via https, but the same holds true for packages regardless of delivery method so I don't see how this is much worse security wise than just declaring dependencies in package.json. Policies does seem to be an effort to solve the integrity issue regardless of how the package is installed, which seems like a good idea to me.
If the caching and integrity issues are resolved well then this would essentially mean package managers become optional, no? Seems pretty good to me!
[1]: https://nodejs.org/dist/latest/docs/api/policy.html https://nodejs.org/dist/latest/docs/api/policy.html