14 ms·
Why NPM in particular? Is there any package manager where you don't have to audit your dependencies?
by root_axis 2y ago
Why NPM in particular? Is there any package manager where you don't have to audit your dependencies?
- lostinsauce 2y agoYes, any repository that uses maintainers and doesn't let anyone upload random stuff to it, like Debian stable. Package maintainers are the missing piece.
- katzinsky 2y agoNPM is particularly nasty because they've solved the issue of transitive dependencies having mismatched versions. This removes one of the biggest immediate pain points caused by having very large dependency graphs so you only feel the pain later on. Because of that you get this emergent behavior of unusually large dependency graphs in a lot of NPM packages.