3 ms·
yeah but those PHP websites are mostly legacy stuff that would completely break if automatically updated to the latest version of any package whereas node.js i
by FrenchDevRemote 4y ago
yeah but those PHP websites are mostly legacy stuff that would completely break if automatically updated to the latest version of any package
whereas node.js is clearly dominant for new websites, and we all use hundreds/thousands of new packages every month without even giving it a second thought
- noduerme 4y agoIs it clearly dominant? I work with both, and for original/personal stuff I'd rather work in Nodejs as a coder (especially if I'm also building the front end)... but I'm still happier as an admin running reliable old Apache/FPM stacks at scale, and that's where the majority of my jobs are. Granted I mostly code in a "boring" non-tech, retail industry these days, but PHP is almost all I deal with in corporate jobs. And supply chain attacks are just not a thing. One reason I asked this question is that I've never built a commercial Nodejs project from the ground up, just my own side projects which aren't particularly sensitive targets... but I'm trying to choose between Nodejs and PHP for a new client's business app which is somewhat sensitive. I'd be a lot more excited to write it in Nodejs, but looking down the road at having to maintain it securely for years I'm not sure. The Nodejs environment and keeping on top of dependencies feels risky right now in a way that's inclining me to use the old familiar PHP. It just struck me as I wrote this that there's a lot I do in PHP that's just part of the language or default plugins, where almost every one of those things requires choosing NPM packages in Nodejs. Even simple stuff like talking to a database or managing sessions or setting up sockets. And the NPM packages get deprecated and renamed, sometimes there are two with very similar names by different authors and it's easy to miss a dash or something. Maybe I'm answering my own question here..
- FrenchDevRemote 4y agoI don't think stuff life talking to a database is actually the problem in Node.js, I think you can trust mongo/mysql packages in NPM just as much as in PHP if you choose the right versions parameters in your package.json. The packages/package manager are not the problem, it's more about the bad habits that you start to get when coding with Node/NPM, basically for every function you write, 9 times out of 10 you can just import a package after 1 import and a command, and so you start to have 200 potential liabilities because you became too lazy to code because it's really easy. But if you stay at least a bit vigilant it's just as safe to use Node.js(or even safer). I think it's really mostly about bad habits rather than the lack of functionality in the language.