5 ms·
The '50 extra packages' one is wild. The author of those packages has racked up a fuckload of downloads. What a waste of total bandwidth and disk space everywhe
by treve 1y ago
The '50 extra packages' one is wild. The author of those packages has racked up a fuckload of downloads. What a waste of total bandwidth and disk space everywhere. I wonder if it's for clout.
- deleted 1y ago[deleted]
- Centigonal 1y agoIt's probably a clout thing, or just a weird guy (Hanlon's Razor), but a particularly paranoid interpretation is that this person is setting up for a massive, multi-pronged software supplychain attack.
- deleted 1y ago[deleted]
- godelski 1y agoThose don't have to be mutually exclusive. Often those with clout are targeted for supplychain attacks. Take xz as an example. Doesn't seem unreasonable that a solo dev or small team looks to either sell their projects or transfer them to someone else (often not even with money exchanging hands). Or even how old social media accounts are hacked so that they can appear as legitimate accounts. I'm big on Hanlon's Razor too, but that doesn't mean the end result can't be the same.
- motorest 1y ago> (...) but a particularly paranoid interpretation is that this person is setting up for a massive, multi-pronged software supplychain attack. That person might not be doing it knowingly or on purpose, but regardless of motivations that is definitely what is being done.
- whilenot-dev 1y agoA package "for-each"[0] that depends on a package "is-callable"[1], just to make forEach work on objects? Nope, not buying the goodwill here. [0]: https://www.npmjs.com/package/for-each https://www.npmjs.com/package/for-each [1]: https://www.npmjs.com/package/is-callable https://www.npmjs.com/package/is-callable
- whilenot-dev 1y agoTo be fair, he himself removed his unnecessary dependency that caused the explosion of dependencies: https://github.com/A11yance/aria-query/commit/ee003d2af54b6bc49a7aba231fedfd0f8b2c8610 https://github.com/A11yance/aria-query/commit/ee003d2af54b6b... EDIT: Oops, he just did the changelog entry. The actual fix was done by someone else: https://github.com/A11yance/aria-query/commit/f5b8f4c9001ba7c7efd20fe6d76bb578c2723de3 https://github.com/A11yance/aria-query/commit/f5b8f4c9001ba7...
- motorest 1y agoOlder browsers don't support foreach, so it's not like a polyfill is unheard of https://caniuse.com/?search=foreach https://caniuse.com/?search=foreach
- whilenot-dev 1y agoAre you serious here? It isn't a polyfill, it's supposed to work on plain objects which isn't part of the spec at all. Besides that, Array.prototype.forEach is only unsupported in Android Browser 4.3 (from July 2013) and IE8 (from May 2008). Seems like a weird reasoning to add it to packages in 2025.
- motorest 1y ago> Are you serious here? I am. If you check the definition of polyfill, you'll eventually arrive at something like the following: > A polyfill is a piece of code (usually JavaScript on the Web) used to provide modern functionality on older browsers that do not natively support it. https://developer.mozilla.org/en-US/docs/Glossary/Polyfill https://developer.mozilla.org/en-US/docs/Glossary/Polyfill I think we would agree that foreach fits the definition, happy path, and whole purpose of a polyfill. if you read up on forEach, you will notice that Array.prototype.forEach requires objects to be callable. https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Array/forEach https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
- nullc 1y ago> is setting up for a massive, multi-pronged software supplychain attack The problem with this view is that the JS ecosystem is already doing that all on its own without that particular contributor. (as has the rust ecosystem, which slavishly copied JS' bad practices). Eliminate the one guy and JS is still pervasively vulnerable to these attacks. The polyfills are the least of it, because at least they should be completely stable and could just be copied into projects. Other dependencies not so much.
- smitty1e 1y agoIt does raise the idea of managed backward compatibility. Especially if you could control at install time just how far back to go, that might be interesting. Also an immediately ridiculous graph problem for all but trivial cases.
- fastball 1y agoThe author is almost certainly ljharb.
- 0x696C6961 1y agoI'm convinced he's a rage baiting account. No-one can consistently have such bad takes.
- antonvs 1y agoYour faith in humanity exceeds mine.
- bikeshaving 1y agoThe maintainer who this piece of “cursed knowledge” is referencing is a member of TC39, and has fought and died on many hills in many popular JavaScript projects, consistently providing some of the worst takes on JavaScript and software development imaginable. For this specific polyfill controversy, some people alleged a pecuniary motivation, I think maybe related to GitHub sponsors or Tidelift, but I never verified that claim, and given how little these sources pay I’m more inclined to believe he just really believes in backwards compatibility. I dare not speak his name, lest I incur the wrath of various influential JavaScript figures who are friends with him, and possibly keep him around like that guy who was trained wrong as a joke in Kung Pow: Enter the Fist. In 2025, I’ve moderated my opinion of him; he does do important maintenance work, and it’s nice to have someone who seems to be consistently wrong in the community, I guess.
- titanomachy 1y agoThis is Wimp Lo! We trained him wrong on purpose, as a joke. Long time since I thought of that movie.
- deleted 1y ago[deleted]
- jddj 1y agoLooking forward to this Jia Tan sequel in a few years' time.
- karel-3d 1y agoto save everyone else a search, it's probably ljharb. (I am not a member of JS community, so, come and attack me.)
- sunaookami 1y agoWow that's some deep rabbit hole. This guy gets paid per XY npm downloads and games the system through this. Awful.
- deleted 1y ago[deleted]