4 ms·
Ironically, I think more dependencies are actually better, because it means they are smaller. "Do one thing well". The problem is large dependencies depending
by erlich 4y ago
Ironically, I think more dependencies are actually better, because it means they are smaller. "Do one thing well".
The problem is large dependencies depending on other large dependencies.
Dependencies should advertise their transitive dependency tree size including LOC per dep.
Also, the fact that every dep has it's own non-standard build process, language, dir structure, and ESM/CJS legacy support, makes things not ideal.
- lolinder 4y ago> Ironically, I think more dependencies are actually better, because it means they are smaller. "Do one thing well". I could believe this if I thought that having 1500 dependencies led to less code overall, but the size of my node_modules folder shows that assumption to be flawed. The other problem with this argument is that each dependency you add is another set of developers that you are depending on. It's another group of people who could suddenly pull a left pad or worse, and it's another group of people who you have to trust to have written secure code. The fewer dependencies I have, the smaller my chances of being exploited because of a people problem.