4 ms·
The worst part about all these node modules is the little small silly ones that do something really inane - like to just get the current year. I said the same
by eric4smith 4y ago
The worst part about all these node modules is the little small silly ones that do something really inane - like to just get the current year.
I said the same thing about some ruby gems years ago and thankfully that’s a little bit sane now.
I don’t use JS that often. But recently I looked at the dependencies for some library I was using and I was astonished at the literally hundreds of tiny modules that were being used.
And it gets even worse - those tiny little modules have their dependencies too.
Amazing.
- encryptluks2 4y agoImagine how easy it would be to exploit one of those too.
- simonw 4y agoRight - every single dependency adds potentially another human maintainer who, if bribed or threatened, could release an update that exploits your project.
- alpaca128 4y agoA project I've been working on has roughly 40 dependencies. If you run `npm install` it'll pull about 1050 npm packages. Change one minor version number and everything breaks. Forget one dependency and npm will not tell you that a dependency is missing but instead it'll complain that Steam has a broken link in the home directory (this is a known open issue for years and the only two solutions are to uninstall Steam or to use a Docker container) Needless to say I am not a fan of large web projects.
- comprev 4y agoAnyone who's run a CI platform for more than a few devs and NodeJS projects quickly bumps into inode problems unless they thought about build server filesystems in advance. Very quickly you end up with hundreds of thousands of minuscule files filling up the disk.
- rglover 4y agoI don't understand why you're getting downvoted. I'm a JS developer (and framework developer) and what you describe is a serious problem. It's great that there's so many problems solved, but some stuff is just a one or two liner that should be in your own app's /lib, not a dependency. This is one reason I like Deno's idea of having a standard library (I just wish Ryan would have proposed that for Node directly instead of creating a brand new runtime).
- monlockandkey 4y agoThe solution to all this dependency mess if for NPM to make a standard library. Yeah that sounds crazy and weird. But they are in the best place to make a unified standard library for Javascript. This would bypass all the junk transitive dependencies and have more libraries rely on a centralised but standard library.
- torgard 4y agoSomeone linked me to 1-liners[0], which is - you guessed it - a bunch of one-liners. I think it's nice to have as a reference. But a dependency? Really? My least favorite is assign. Not only does JavaScript feature that natively (though I suppose the library may predate widespread support for Object.assign), the 1-liner assign flips the order of the parameters! assign({ a: true }, { a: false }) -> { a: true } Object.assign({ a: true }, { a: false }) -> { a: false } And most of them are just straight-up pointless! Like, let's introduce a dependency for decrement lol EDIT: In looking up whether the 1-liners assign predated widespread Object.assign support, I found that their implementation - confusingly named extend[1] at first - literally used Object.assign from the very beginning. And they still chose to mess with the parameter order. For shame lol [0] https://github.com/1-liners/1-liners https://github.com/1-liners/1-liners [1] https://github.com/1-liners/1-liners/blob/7c1f8d51df4b4b3e0a16d0ace8864eafcbac5483/module/extend.js#L17 https://github.com/1-liners/1-liners/blob/7c1f8d51df4b4b3e0a...
- jeroenhd 4y ago> Like, let's introduce a dependency for decrement lol Here's a package that basically does that: https://www.npmjs.com/package/number-precision https://www.npmjs.com/package/number-precision Not entirely unreasonable as all `number`s are floats by default in JS, but the implementation of the entire package (https://github.com/nefe/number-precision/blob/master/src/index.ts https://github.com/nefe/number-precision/blob/master/src/ind...) is less than 100 lines of code and actually contains a method called "minus". The very worst JS packages I've seen have got to be is-odd and is-even. 430,796 and 202,268 downloads every week, I kid you not!
- viraptor 4y agoSeems like a perfect candidate for a drive by fix. If you see it in your dependency tree, fix it in the project that uses it.
- samatman 4y agoIt would appear this argument order is due to Principle 5: Data comes last, for consistent currying. You might not like it, or the library (I don't write JS on purpose, so no opinion), but it's right there in the README.