4 ms·
It really depends what ecosystem you are in. For example, the nodejs/npm ecosystem is on a never-ending cycle of package upgrades. If a maintainer is not main
by StressedDev 3y ago
It really depends what ecosystem you are in. For example, the nodejs/npm ecosystem is on a never-ending cycle of package upgrades. If a maintainer is not maintaining a package, it will eventually have to be replaced for one of the following reasons:
1) One of the package's dependencies has a breaking change which breaks the package
2) One of the package's dependencies has a security bug. The dependent package cannot be upgraded to a fixed version because the dependent package's fixed version has a breaking change which breaks the original package.
Basically, ecosystems which do not have strong backwards compatibility tend to require packages/libraries/creates/assemblies/DLLs to be maintained forever.
- Falkon1313 3y agoThat seems like a really good reason not to use that ecosystem. It's not the fault or the problem of the person who created the open-source project. If you choose to use open source code in a system like that, then that's what you've chosen.