8 ms·
Have we all forgotten the left-pad incident? This is an eco system that has taken code reuse to the (unreasonable) extreme. When JS was becoming popular, I’m
by 2muchcoffeeman 1y ago
Have we all forgotten the left-pad incident?
This is an eco system that has taken code reuse to the (unreasonable) extreme.
When JS was becoming popular, I’m pretty sure every dev cocked an eyebrow at the dependency system and wondered how it’d be attacked.
- zelphirkalt 1y ago> This is an eco system that has taken code reuse to the (unreasonable) extreme. Not even that actually. Actually the wheel is reinvented over and over again in this exact ecosystem. Many packages are low quality, and not even suitable to be reused much.
- wongarsu 1y agoThe perfect storm of on the one side junior developers who are afraid of writing even trivial code and are glad if there's a package implementing functionality that can be done in a one-liner, and on the other side (often junior) developers who want to prove themselves and think the best way to do that is to publish a successful npm package
- bobthepanda 1y agoThe blessing and curse of frontend development is that there basically isn't a barrier to entry given that you can make some basic CSS/JS/HTML and have your browser render it immediately. There's also the flavor of frontend developer that came from the backend and sneers at actually having to learn frontend because "it's not real development"
- pxc 1y ago> There's also the flavor of frontend developer that came from the backend and sneers at actually having to learn frontend because "it's not real development" What kind of code does this developer write?
- garbagepatch 1y agoAs little code as possible to get the job done without enormous dependencies. Avoiding js and using css and html as much as possible.
- sfn42 1y agoSounds like the perfect frontend dev to me.
- cluckindan 1y agoThe designer, the customer, and US/EU accessibility laws heavily disagree.
- Philadelphia 1y agoHow is javascript required for accessibility? I wasn’t aware of that.
- boesboes 1y agoIt is not. In fact, it is all the modern design sensibilities and front-end frameworks that make it nearly impossible to make accessible things. We once had the rule HTML should be purely semantic and all styling should be in CSS. It was brilliant, even though not everything looked as fancy as today.
- cluckindan 1y agoJS is in fact required for AA level compliance in some cases, usually to retain/move focus appropriately, or to provide expected keyboard controls. https://www.w3.org/WAI/WCAG22/Techniques/#client-side-script https://www.w3.org/WAI/WCAG22/Techniques/#client-side-script Also, when was that semantic HTML rule? You make it sound like ancient history, but semantic HTML has only been a thing since HTML5 (2008).
- zelphirkalt 1y agoHa, that's a funny attitude. And here I was thinking, that mostly doing backend work, I rather make the best out of the situation, if I have to do frontend dev, and try to do "real development" by writing trivial things myself, instead of worsening the situation by gluing together mountains of bloat.
- whstl 1y agoPeople pushing random throwaway packages is not the issue. A lot of the culture is built by certain people who make a living out of package maximalism. More packages == more eyballs == more donations. They have an agenda that small packages are good and made PRs into popular packages to inject their junk into the supply chain.
- smaudet 1y agoI found it funny back when people were abandoning Java for JavaScript thinking that was better somehow...(especially in terms of security) NPM is good for building your own stack but it's a bad idea (usually) to download the Internet. No dep system is 100% safe (including AI, generating new security vulns yay). I'd like to think that we'll all stop grabbing code we don't understand and thrusting it into places we don't belong, or at least, do it more slowly, however, I also don't have much faith in the average (especially frontend web) dev. They are often the same idiots doing XYZ in the street. I predict more hilarious (scary even) kerfuffles, probably even major militaries losing control of things ala Terminator style.
- hshdhdhj4444 1y agoIt’s not clear to me what this has to do with Java vs JavaScript (unless you’re referring to the lack of a JS standard library which I think will pretty much minimize this issue). In fact, when we did have Java in the browser it was loaded with security issues primarily because of the much greater complexity of the Java language.
- lmz 1y agoIt's not the language it's the library that's not designed to isolate untrusted code from the start. Much harder to exit the sandbox if your only I/O mechanism is the DOM, alert() and prompt().
- smaudet 1y agoAnd the whole rest of the Internet... The issue here is not Java or it's complexity. The point is also not Java, it's incidental that it was popular at the time. It's people acting irrationally about things and jumping ship for an even-worse system. Like, yes, if that really were the whole attack surface of JS, sure nobody would care. They also wouldn't use it...and nothing we cared about would use it either...
- lmz 1y ago
- darkwater 1y agoNot on HN, the land of "you should use a SaaS or PaaS for that (because I might eventually work there and make money)" or "I don't want to maintain that code because it's not strictly related to my CRUD app business! how you dare!"
- fatchan 1y ago1.2 million weekly downloads to this day, when we've had builtin padStart since ES2017. Yes, I remember thinking at the time "how are people not ashamed to install this?"