3 ms·
That's a tremendous expectation. There are 913 node_modules in the first project I glanced at. That's millions of lines of code.... More than one person can rea
by jackconsidine 5y ago
That's a tremendous expectation. There are 913 node_modules in the first project I glanced at. That's millions of lines of code.... More than one person can reasonably audit even if it's their full-time job. Where would this responsibility end? Should they also be auditing Node.JS source code? And nightly browser builds? No, we necessarily federate our trust at some point in these things being raised by others (like now, albeit 23 days late).
- exfascist 5y agoI don't run nigtly browser builds because that's too much to keep up with. I have actually read quite a bit of the code for the browser I use. I read almost everything I deploy because I'm responsible for it. Using other people's code absolves you from maintenance but not responsibility, that's something people need to start understanding. It's a very reasonable expectation that you read through your dependencies, if it's too much then it's time to trim some fat.
- pabs3 5y agoThere is a distributed code review system that is intended to make it feasible to do the necessary review: https://github.com/crev-dev/ https://github.com/crev-dev/
- JohnHaugeland 5y agoIt seems like you're attempting to suggest that third party javascript is on equal trust footing with major tools and things by international corporations
- jackconsidine 5y agoMy point was that it's unreasonable to expect the exhaustive audit of all node modules. That said, "major tools and things by international corporations" like Gatsby depend on the topic library [0]. https://www.npmjs.com/browse/depended/event-source-polyfill https://www.npmjs.com/browse/depended/event-source-polyfill