5 ms·
For scripts, it's pretty sweet to be able to import dependencies directly via URL without needing to do an `npm init` and `npm install`. For larger projects (li
by binarynate 5y ago
For scripts, it's pretty sweet to be able to import dependencies directly via URL without needing to do an `npm init` and `npm install`. For larger projects (like my static site generator), I didn't find it tedious to import from a central deps.ts file, although I admit that importing from a relative path like '../../deps.ts' is not as quite as nice as importing by package name like in Node. I'm OK with that the tradeoff, though, especially since it matches the way imports work in the browser.
- dmitriid 5y agoWhat about transitive dependencies?
- galaxyLogic 5y agoMy question too. I assume Demo downloads one component and then all its nested dependencies. But now every nested dependency can come from a different server, just like the components you refer to can come from anywhere on the internet. I wonder if this could be a security issue. It's hard to know who has control over all those nested repositories, and who keeps a look on them to ensure they are not maliciously modified? Is anybody checking on cryptographic signatures of them? Only asking because I don't know much about Demo.
- int_19h 5y agoLocked modules have their hashes stored, so if something does change, you'll know right away. So will anybody else who got the source from you with lock.json included.
- dmitriid 5y agoSo, this is kinda unusable for any corporate setting where all dependencies, including transitive ones, are downloaded from a private server.
- int_19h 5y agoEr, why? You'd just set up an import map to point it at your private server.
- dmitriid 5y ago> You'd just Ah. The enievitable "just". And how exactly do you set the import map to point to the private server for the transitive dependencies? Deno's own docs don't bother with such trivialities and show a very toy example, of course, https://deno.land/manual/linking_to_external_code/import_maps https://deno.land/manual/linking_to_external_code/import_map...