13 ms·
“You meant to install ripgrep”
- typon 4y agoNeovim + Telescope + ripgrep. It's taken 30 years, but we finally have the perfect code navigation solution.
- aidos 4y agoAmen to that!
- benreesman 4y agoIn spite of some tense conversations with the author I am still a rg super fan: it’s fantastic, reliable, performant, well-maintained software and I would recommend it to anyone. It’s best in class.
- secondcoming 4y agoIs it faster than Silver Searcher (ag)?
- burntsushi 4y agoYes. And less buggy. If someone can find a meaningful case where ag is faster than ripgrep, then I'm happy to accept a bug report. I'll do my best at that point to give an analysis of the benchmark, and if it's correct, I'll either try to fix it or say why it's hard to fix. By "meaningful" I mean "something that is noticeable to humans." So for example, reporting a bug because ripgrep took 9ms and ag took 7ms on a tiny repo is one I would consider not meaningful. :) (Sorry about the verbose caveats, but just trying to head off responses I've got in the past.)
- Lapsa 4y agolong time silver searcher user here. made a switch to rg and haven't looked back. although ag is still a tool of that rare breed I really have nothing bad to say about.
- thombles 4y agoTo my knowledge this is the only wrong crate I've ever installed due to my own error. It's... not a good feeling to read this message, even though the author turned out to be doing me a favour. :)
- chlorion 4y agoIt would be nice if crates supported being signed with GPG or minisign or whatever. I can imagine for example, importing keys from only the authors that I think I can trust, and passing a flag to cargo that only allows using those packages for cargo install or cargo add. In this case I think just checking the top level crates signature (and not dependencies) would be enough to mitigate a lot of issues including typo squatting.
- burntsushi 4y ago'cargo crev' makes this kind of workflow possible: https://github.com/crev-dev/cargo-crev https://github.com/crev-dev/cargo-crev
- richdodd 4y agoCan't recommend `cargo crev` enough!!! The more people use it, the more powerful it becomes.
- low_tech_punk 4y agoWhat is in the mysterious `rg` crate? There is no doc.
- fregante 4y agoBack when npm didn’t have any “similar name” restrictions I did the same for some popular packages. My redirects also helped me a couple of times as I wonder whether a package name had a dash or not. https://github.com/fregante/npm-helpful-typosquatting https://github.com/fregante/npm-helpful-typosquatting Here’s what it looks like: https://www.npmjs.com/package/webext https://www.npmjs.com/package/webext
- ashishbijlani 4y agoTools like Packj[1] that check for typosquatting and install packages under a sandbox can help in avoiding accidental installation of malicious packages. Disclaimer: I’m one of the devs. 1. https://github.com/ossillate-inc/packj https://github.com/ossillate-inc/packj
- totorovirus 4y agoWhy no alias linking or clone? Is it technically impossible?
- notorandit 4y agoLife is too short to spend time just to know what ripgrep is/does. I mean, yes, you all look so cool and I look so dumb. But, c'mon, is this software so complex that its description doesn't fit 42 words? Is like having a shop with no sign and no window. Everyone is saying it's great and worth shopping. But still no sign. Ridiculuos.
- Lapsa 4y agoyou search stuff with it
- harry8 4y agoSo it's grep like i already have installed and know its quirks?
- Lapsa 4y agoyeah but with less quirks and runs much faster. worth trying out
- harry8 4y agoUses regexes = has quirks.
- harry8 4y agoSeems this comment was a bit subtle for some people. Moving to a different set of quirks is not a step forward than continuing to use the ones you know. Regexes aren't de-facto standard; grep is different to egrep to perl to python to C++ to your text editor to whatever. It's a massive pain and annoying as fudge. You're a programmer you know this. A "superior" set of quirks may be better for new regex users but it is worse for everyone else who now has to know both grep (and all the other regex quirks) and ripgrep if they're going to use it. To get this done like I always have I now need to know something new. A new user doesn't care about the obsolete. Faster? Well I have not yet experienced an issue with the speed of grep, that's my experience. I can imagine this could be compelling for uses I don't know about. ripgrep may well be a better grep for some users. And that is Great, really! We should all try and make things better! Hurrah! Refusing to describe how it is different and why you might like to install something non-standard (for which there could be compelling reasons) is just silly. Hyping anything at all in that context like that looks pretty bad. The ratio of content-free hype (omg ripgrep is fantistic!) to an actual description on this thread or in the link or seemingly anywhere I clicked is pretty bad and constitutes a signal.
- bmn__ 4y agoSimilar: http://p3rl.org/install http://p3rl.org/install
- rpigab 4y agoI never run cargo install or any other package manager download commands without checking the website of the package manager for the right name first, ensuring the author is right, and the commit/update history looks right. I love Python but pip/pypi and imports always felt wierd to me because of namespaces, package names, special imports "as", etc., maybe this is a bias because I started using them when I was younger and now I'm more experienced, I already know how to use most package managers. BTW Ripgrep is awesome, I'm learning Rust and it's an inspiration to me, thanks burntsushi!
- richdodd 4y agoHi - author of `rg` here :'). I've transferred over to BurntSushi which will give people a bit more assurance that `rg` won't become malware in the future. I also squatted `memap` and `memap2` for the same reasons. I wonder if there is an algorithmic way to decide when two crate names are 'near' each other. Then, if you added a crate with `cargo add` and there is another similarly-named crate with much higher usage, a warning could be emitted. *EDIT* I know there's already https://en.wikipedia.org/wiki/Levenshtein_distance https://en.wikipedia.org/wiki/Levenshtein_distance, but I wonder if there is a better measure that looks at e.g. keyboard layouts and likely typos. I'm sure there will have been research done on this.
- burntsushi 4y agoThank you! I've updated the crate to use dtolnay's suggestion (a compilation error), added a short README and created a repo for it with a small FAQ: https://github.com/BurntSushi/rg-cratesio-typosquat https://github.com/BurntSushi/rg-cratesio-typosquat
- micouay 4y ago`rg` has only one version, and one line of code: println!("You meant to install ripgrep: type `cargo uninstall rg` followed by `cargo install ripgrep`");
- dtolnay 4y agoSeems like it would be better to contain: compile_error!("You meant to …"); so that the install would fail and `cargo uninstall rg` wouldn't be needed.
- burntsushi 4y agoYeah that sounds much nicer.
- taink 4y agoCan always-failing-to-compile crates be deployed to the registry?
- orf 4y agoYes
- Arnavion 4y agocrates.io doesn't try to build crates. It couldn't do that anyway. Crates can require arbitrary C library dependencies, only run on some specific targets, etc. That's why docs.rs has to make some effort to be able to build crates, and even it doesn't get all of them.
- oconnor663 4y agoYes, `cargo publish` has the `--no-verify` flag if you want to force this. I think all the verification is client-side.
- est31 4y agoThere is some server side verification, mostly around checking that the dependencies all exist, the file isn't too large, etc. But 99% of the testing happens on the client. Eg: https://github.com/rust-lang/crates.io/blob/58e505f2abdabd6a7334357d573a1486d4fa60f1/src/controllers/krate/publish.rs#L386-L437 https://github.com/rust-lang/crates.io/blob/58e505f2abdabd6a... https://github.com/rust-lang/crates.io/blob/58e505f2abdabd6a7334357d573a1486d4fa60f1/src/controllers/krate/publish.rs#L325 https://github.com/rust-lang/crates.io/blob/58e505f2abdabd6a... https://github.com/rust-lang/crates.io/blob/58e505f2abdabd6a7334357d573a1486d4fa60f1/src/controllers/krate/publish.rs#L278 https://github.com/rust-lang/crates.io/blob/58e505f2abdabd6a... https://github.com/rust-lang/crates.io/blob/58e505f2abdabd6a7334357d573a1486d4fa60f1/src/views/krate_publish.rs#L16-L36 https://github.com/rust-lang/crates.io/blob/58e505f2abdabd6a...
- burntsushi 4y agoHah! TIL. I had no idea someone did this. But it's smart. I should have thought of it! (I'm the author of ripgrep.)
- nicce 4y agoIt is smart, in multiple ways. For some guys who don’t know why, it prevents supply chain attacks.
- aryik 4y agoUnrelated, but thank you for your work! You’ve saved me tens if not hundreds of hours with ripgrep, and I’ve become a huge evangelist of it at my workplace. When I’m helping someone understand how to debug customer issues, the first thing I tell them is to install ripgrep. Truly a fantastic piece of software.
- burntsushi 4y agow00t! Thanks for the kind words. :-)
- lillecarl 4y ago"gron | rg", because life is too short to learn jq. Amazing work on rg!
- tambourine_man 4y agoOMG, thank you. jq is great but its syntax is impossible to memorize. This is so much better.
- lillecarl 4y agoAny time! Yeah jq is great, but my usecase is covered better by these two together. Truly the Unix philosophy at it's finest. It's the only way I search JSON these days! (or YAML with "yq | gron | rg" to get results, pop into (n)vim and to my thing :)
- seanw444 4y agoIs there no way to have a package mirror, or alias or something? Unless I'm missing a joke or something, this seems like an easily solvable problem.
- VWWHFSfQ 4y agoI think you would rather have explicitly named dependencies. I don't want a bunch of aliased dependencies redirecting to wherever
- stjohnswarts 4y agoI'm the same, I'd rather it be broken so I can figure out what's going on rather than bounced around all over the place.
- kevincox 4y agoIt is likely better to get the error and fix the mistake than be relying on an redirect owned and operated by who-knows-who indefinitely.
- woodruffw 4y agoAliases turn a flat namespace into a potentially cyclical graph, and introduce all kinds of permission considerations (Should a non-owner be able to alias a project? If so, should they be allowed to update it?). The solutions here are non-flat namespacing (which has worse UX, since `cargo install some-tool` now becomes `cargo install whats-their-handle-again/some-tool`) or some kind of content addressing (which is similarly bad for UX, if not worse). Most package indices choose neither, and "solve" the problem by playing whac-a-mole with abuse instead.
- tomjakubowski 4y agoClojars has the right idea for namespacing: some-tool is an alias for some-tool/some-tool. This means the first package to squat on the name can use the shorthand version, while allowing other packages with the same name in other namespaces. (which may be forks or entirely different packages)
- noswi 4y agoWhat does one do if they wish to see the actual contents of this crate? The web interface I'm looking at contains no hints at peeking inside, not even direct archive download links, nothing. I can't believe that a good way to see what's inside is to make a rust project, add the crate and then go searching around the local filesystem.
- pie_flavor 4y agoThe source is hosted alongside the documentation at https://docs.rs https://docs.rs. But far simpler than that is just going to the prominent GitHub link.
- maxbond 4y agoIn this case, there isn't a GitHub link, as there's no repository in the Cargo.toml: https://docs.rs/crate/rg/0.1.0/source/Cargo.toml https://docs.rs/crate/rg/0.1.0/source/Cargo.toml
- ripley12 4y agocrates.io is a little bare-bones sometimes. I usually use lib.rs instead: https://lib.rs/crates/rg https://lib.rs/crates/rg That has a link to source: https://docs.rs/crate/rg/0.1.0/source/ https://docs.rs/crate/rg/0.1.0/source/ And here's the Rust code: https://docs.rs/crate/rg/0.1.0/source/src/main.rs https://docs.rs/crate/rg/0.1.0/source/src/main.rs
- remram 4y agoSimilar in the Python world: https://pypi.org/project/sklearn/ https://pypi.org/project/sklearn/ This one just depends on the correct `scikit-learn` package though.
- learndeeply 4y agoSame for: https://pypi.org/project/pytorch/ https://pypi.org/project/pytorch/ > You tried to install “pytorch”. The package named for PyTorch is “torch”
- walthamstow 4y agoAlso bs4 / beautifulsoup4
- OJFord 4y agoThese are both like numpy & pandas in always documenting with `import longname as ln` right? I think they bring it on themselves.
- remram 4y agoNo, it's worse, if you `pip install scikit-learn` you get a library importable as `import sklearn`. It's more than a usage or documentation issue, the code itself doesn't match the name on the can. (and `pip install beautifulsoup4` lets you `import bs4`)
- woodruffw 4y agoThis classic version of this in the Ruby ecosystem is "bundle"[1], which helpfully installs `bundler` for you. Of the 6.7 million downloads it has, I'm probably in there a dozen or so times. [1]: https://rubygems.org/gems/bundle https://rubygems.org/gems/bundle
- willlll 4y agoI appreciate each and every download.
- steveklabnik 4y agoThere’s also “nokogirl”
- underyx 4y agoI maintain a Python package that parks names like this. There's a Python library called pypi-parker[0] that makes it really easy to do this via CI. [0]: https://pypi.org/project/pypi-parker/ https://pypi.org/project/pypi-parker/
- woodruffw 4y agoFor what it's worth: using a tool like pypi-parker technically violates PEP 541[1], since it uploads projects with no functionality solely to reserve parts of the namespace. You may or may not get away with using it, depending on how you use it, but PyPI's admins (who I do not speak for) would be within their enumerated rights to ban any account that uses it to squat names. [1]: https://peps.python.org/pep-0541/#invalid-projects https://peps.python.org/pep-0541/#invalid-projects
- underyx 4y agoThanks for flagging this, I was unaware! I agree with your assessment; I just hope that this is considered to not be in breach of the spirit of the PEP. It seems like the PEP intended to disallow squatting in terms of pre-emptively reserving and hogging names, the way domain squatters do it. So hopefully typosquatting prevention for the sake of security is considered fine by the admins; especially since our project was designated a 'critical project' and stricter security measures apply to our maintainers.
- jfk13 4y agoHuh - the same author also has https://crates.io/crates/memap https://crates.io/crates/memap and memap2, which explicitly say that they're "squatting to prevent a malicious typo package". Not sure how to feel about this... on an individual-package level, it seems a sensible enough idea, but if it becomes a widespread practice, the namespace could get really cluttered.
- KMnO4 4y ago> but if it becomes a widespread practice, the namespace could get really cluttered. Crates.io is incredibly cluttered with namesquatting. It’s probably the worst package registry for it, even surpassing NPM. Part of the problem is that they explicitly say name squatting isn’t against the rules.
- sedatk 4y agoI guess "owner/packagename" convention could solve such issues as it's common with other package ecosystems.
- Macha 4y agoJust moves the problem to packagename/packagename looking like a more "official" source.
- burntsushi 4y agoRight. So then you add burnsushi/ripgrep instead. See the problem? Namespaces are a solution or mitigation to some problem, but that problem is not malicious typo-squatting.
- sedatk 4y agoFor malicious intents, yes. But, for legitimate reasons where you need to have an "rg" package with a completely different use case, owner namespaced packages might provide a uniform solution.
- 4y ago
- deleted 4y ago[deleted]
- samatman 4y agoIf a package manager is starting from zero, and wants to have a privileged namespace such that a short name has a canonical value, it would make sense for those packages to be able to include a list of strings which the package should also reserve. That way "ripgrep" could include "rg", searching cargo for "rg" brings back "ripgrep", not a second package named "rg", and an install could tell the user the correct name for any attempt to install it. This also covers typo-squats, so there would be no need for packages like "memap". Obviously this represents a low-effort vector for massive squatting, so maintainers would need to be responsible for preventing that, and could add some typos themselves, being the ones which see the request for the mis-typed packages.
- karmanyaahm 4y agoWhile (afaik) this is not supposed to be used for typos, Arch Linux' provides enables 'synonyms' to be registered. https://wiki.archlinux.org/title/PKGBUILD#provides https://wiki.archlinux.org/title/PKGBUILD#provides
- 6keZbCECT2uB 4y agoI use fzf with an text file which lists all files installed by a package with the package name. That way if I know the header name, I can get the package name. If I know the package name, I can get all its files.
- mherdeg 4y agoWow, it's been years now since I typed "sl" at a terminal and got an ascii steam locomotive.
- rsr 4y agoA friend of mine in college installed this on my laptop when I had my back turned. For a month or so, I wondered why anyone thought this feature was a good idea, and why no one I knew who used MacOS seemed to complain about it.
- deleted 4y ago[deleted]
- jimjimjim 4y agoit's a nice touch that sl includes a man page and command line flags
- lifthrasiir 4y agoIt was a helpful reminder to finally learn Ctrl-\ for SIGQUIT.
- __henil 4y agoTIL!
- c7DJTLrn 4y agoCrates should be namespaced by user. This is a disaster waiting to happen.
- remram 4y agoDo you change the name every time there is a change in the maintainers' team? If you have `ripgrep-team/ripgrep` rather than `ripgrep`, it doesn't help at all with people typing the wrong thing, like `rg-team/rg`. I fail to see how it helps. It's even worse with packages that are (currently) authored by a single person, how many people know the name of ripgrep's author? Or rand? Or bevy?
- stjohnswarts 4y agoI don't think so. ripgrep could easily become super cluttered if any john-joe-jimmy-larry could namespace it
- pornel 4y agoThen you'd have people installing "burnedsushi/ripgrep" instead of "burntsushi/ripgrep". It only kicks the problem one step down without fixing it.
- jrochkind1 4y agoworse, if the correct one was `burntsushi/ripgrep`, someone else would just squat `ripgrep/ripgrep`.
- PartiallyTyped 4y agoI agree, same for PyPI and all package repositories.
- filereaper 4y agoCan't tell you how often I've run: `pip install aws` This installs a library by some authors not affiliated with AWS. Instead of: `pip install awscli` Which is what you expect.
- RulerOf 4y agoI'm frequently worried that I'm going to install malware on my machine doing this one of these days.
- debacle 4y agoWhat is ripgrep? Edit: Because I'm on a Zoom call that will never end. "ripgrep is a line-oriented search tool that recursively searches the current directory for a regex pattern. By default, ripgrep will respect gitignore rules and automatically skip hidden files/directories and binary files." https://github.com/BurntSushi/ripgrep https://github.com/BurntSushi/ripgrep
- kibwen 4y agoA grep alternative that optimizes for performance: https://github.com/BurntSushi/ripgrep https://github.com/BurntSushi/ripgrep . There are detailed performance comparisons and discussions in the readme there.
- tmtvl 4y agoA file searcher akin to grep, ack, or ag (aka the silver searcher) it's programmed in Rust so it is decently fast with good support for UTF-8. Unfortunately it defaults to parsing a git tree's gitignore file and skipping over files listed in it.
- stjohnswarts 4y agojust use --hidden, people shouldn't be afraid of typing an additional word. I prefer the defaults to keep things clean.
- kevincox 4y ago"decently fast" is a significant understatement. It is likely the fastest similar tool. (`git grep` may win due to not listing the directory tree and packed files and GNU grep is very fast if you don't use Unicode, but other than that ripgrep wins).
- Sohcahtoa82 4y ago> Unfortunately it defaults to parsing a git tree's gitignore file and skipping over files listed in it. That's a feature. Like, it's the entire point of ripgrep. It's designed to search through the things a developer actually cares about searching through. If you actually want to search everything, just use grep.
- worewood 4y agoWhy not just add ripgrep as a dependency, effectively making it an alias of the original package?
- stjohnswarts 4y agoNah KISS
- burntsushi 4y agoI wouldn't sign off on this personally. It makes auditing harder. You see `cargo install rg` somewhere, but you also see that `cargo install ripgrep` is what's listed in ripgrep's README. So now you wonder, is `cargo install rg` correct? Then maybe ripgrep has to add a note about this to the README, and maybe you see it, maybe you don't. Better to just make `cargo install rg` fail so that it never worked in the first place. `cargo install ripgrep` is also more self-describing and gives you a better search engine query.
- kevincox 4y agoWould this install the binaries of the dependency to your $PATH? I would expect that only the top-level package would be "installed" that way.
- Longwelwind 4y agoMaybe it's only for me, but I've never liked this of too-smart solutions. Let people do the mistakes once and learn the correct package name, instead of relying on a hack and potentially introduce confusion later.
- yellowapple 4y agoNot to mention adding a juicy target for malicious shenanigans.
- 3a2d29 4y agoThis would work, but I think hiding a package behind an alias is never a good idea.