5 ms·
My temporary PHP fix from 2014 has nearly 20M installs. Today I'm deprecating it
- jakeasmith 18d agoAuthor here, happy to answer any questions. I never imagined a polyfill for http_build_url would gain so much traction. After 12 years, deprecating it feels like the right move, especially given the new options from the community and PHP itself.
- HackerThemAll 16d agoThe JavaScript world is littered with stuff comparing to which your patch seems like a complex project. See those examples: https://www.npmjs.com/package/is-odd https://www.npmjs.com/package/is-odd https://www.npmjs.com/package/is-even https://www.npmjs.com/package/is-even https://www.npmjs.com/package/left-pad https://www.npmjs.com/package/left-pad https://www.npmjs.com/package/is-whitespace-character https://www.npmjs.com/package/is-whitespace-character https://www.npmjs.com/package/isarray https://www.npmjs.com/package/isarray
- JaggerJo 16d agowhat a broken ecosystem.. The crazy thing is not that the package exists, but that it is used by JS devs.
- yurishimo 16d agoThere’s a bit more nuance as to why. It’s not fair to say that the average JS dev is reaching for a package like is-odd/is-even. Years ago when npm was just getting started there was a lot of experimentation and land grabbing for packages. A few “prolific” developers were pushing these tiny utilities and then using them in their own projects which ended up being required as deps in other projects and then snowballed into is-odd being included in webpack at some point (I think I have that timeline roughly correct). It’s still a crappy problem for sure but it’s not fair to paint most JS devs with a brush so broad.
- junon 16d agoI feel like I have to remind people of this quite often, but the history is such that npm was lightweight at one point, bundling wasn't a thing, and while `isodd`/`iseven` are of course silly, things like `isarray` were not functions that existed back then (we didn't have Array.isArray). `typeof [] === 'object'` in JS, so e.g. my package `is-arrayish` checked for a similar structure to an array (whereas Id guess `isarray` checked for the prototype). `isarray` failed for the `arguments` keyword, which was needed for variadics before argument spreads were added to the language I believe in ES5. So of course they don't make sense now. But they were created for a reason. Before even Markov chains were a fad - let alone LLMs - we were trying to be as efficient as possible and maximize code reuse I stead of writing the same helper functions over and over again. That's what you're seeing.
- b112 16d ago[flagged]
- zarzavat 16d agoYes and the critical issue was tree shaking. Nowadays we have tree shaking so it doesn't matter as much but in the past people preferred small single function packages because they had less impact on the download size.
- ChiperSoft 16d agoAdditional Context: for about two years functional programming was REALLY popular in the Node community. It was a fad to chain tons of tiny functions together, and thus lots of people wrote tons of tiny functions. This is why lodash/fp exists.
- austin-cheney 16d agoEverything that touches JavaScript in the corporate world feels broken. Look at any full stack job post. It’s a mess of tech stack nonsense on the backend for people who are terrified of JavaScript and a layering of framework madness on the frontend for people who are still terrified of JavaScript. So it should be no surprise to see packages like those in common use when people aren’t really writing, or even reading, the real code anyways. That is just the coding aspect of it. There are many additional challenges to working with a bunch of cowards whose primary job is to pretend to be something they clearly aren’t.
- dahart 16d agoThere’s not much evidence these are being used, only that they are dependencies for something else; that’s why the download numbers are so high. I wouldn’t say it’s broken, I’d say there are tradeoffs, and devs have known this and discussed it since the start of npm or any package manager. You automatically get some bloat when you use other people’s software. That’s the downside. The upside is you don’t have to write the code yourself and you can create things more quickly by not solving problems that others have already solved. It’s worth noting that AI has some of the same tradeoffs. The quality of what you get is still proportional to your prompting & reviewing effort, and spending low amounts of effort often results in similar amount of bloat.
- shevy-java 16d agoPHP devs are happy that npm exists. That way there is always a worse ecosystem down below.
- domh 16d agoThese packages are basically memes at this point... Those download figures cannot be accurate for real production usage. I don't believe any programmer is actually using these. isarray and left-pad are at least functions that didn't used to be in the standard library, to slightly excuse them.
- sumtechguy 16d agoI would not bet on that assumption. I have seen some wild code over the years from devs. With 'ai' type coding going on now too you may see them be used even more.
- domh 16d agoI would've actually thought AI would slightly improve upon this situation. At least in my experience claude seems to write a lot more little utility functions itself rather than reaching for a package from npm to do something. Requiring an `npm install` before getting something working risks triggering a permissions gate.
- brookst 16d agoOpus and fable both are pretty judicious about bringing in dependencies, at least for me. They often argue against and and write even decently large modules to avoid pulling stuff in.
- sire-vc 16d agoThey never install packages for me and love handrolling large amounts of e.g. parsing code where a library exists. I have to keep telling them 'look for a large popular dependency' when they start writing huge functions that obviously already exist. Was doing something with OSM the other day and Opus basically started reimplementing NetTopologySuite.
- whywhywhywhy 16d agoMajor libraries used them so yeah the numbers are real, left-pad was in every react and babel install.
- vachina 16d agoWhenever I see a npmjs project I nope out of it. I’d rather spend $50 on tokens to reimplement whatever JS slop in Python or Go.
- JohnMakin 16d agois-even implementation: > 'use strict'; > var isOdd = require('is-odd'); > module.exports = function isEven(i) { > return !isOdd(i); > };
- d3Xt3r 16d agoI thought you were joking, but then I checked the code... holy shit, it is real. Surely the author's gotta be trolling, right?
- layer8 16d agoI’d say the deciding factor is that it has bugs where both fixing and not fixing them can have a negative impact. If there were no known bugs and there was no harm in using it, I’d probably just leave it there and not disturb anything, given that its use is so widespread, and instead merely note in the documentation that its purpose has become obsolete.
- dolmen 16d agoFrom the article: > So I had a decision to make. I could dive back into PHP after almost a decade away, hand the package to one of the people who’d offered, or let it keep sitting there. We are in the AI era. As a maintainer of an open source project that I haven't touched for years, I would first start by asking an AI to produce a fix for the issue and check what it proposes. This definitely reduces the mental load and risk of breaking an old codebase that so many users depend on. Deprecating the project is playing the open source game in an other dimension: tell the word that depending on this project was a bad idea in the first place and that everyone should move on. But releasing a fix on a deprecated project is fine too. So both actions are on different dimensions, this isn't a choice between 2 options.
- jjice 16d agoThe man released a fix twelve years ago for free. If someone is really depending on this, they can fork it themselves. I'd argue that that's the beauty of open source, rather than a downside.
- mech422 16d agoThe down vote was me - I really think calling deprecating a project after a decade+ telling the world 'depending on this project was a bad idea' is tone deaf.
- lukeify 16d agoOthers would say pragmatic.
- iso1631 16d agoI think it shows a complete misunderstanding on what free software is.
- dspillett 16d agoFree software is Free (and free software is free, libre software is libre, …, where the free/Free/libre/OS/… distinctions are relevant). That does not guarantee continued maintenance for decades, and to expect such is the sort of entitlement that puts some people off sharing their work and playthings.
- jmathai 16d agoI have written A LOT of PHP in my life. Not so much anymore but I only have fond memories of the community - thanks to folks like you. Kudos.
- amhoab 17d agoWe used to work together at AOL. Glad to see you on here; I hope you're doing great!
- yard2010 17d agoReading this threw me back to 2014 - how was working for AOL back then?
- Macha 16d agoI worked there around that time, and a little later. The company had recently ish gotten independent and was actually pretty optimistic. The basic plan was to use the clearly dying dialup business to fund new businesses in media and ads, and there was even hope that the mail and search stuff could be turned around. I think the ads and media stuff broadly worked, most of the media businesses are still going though they were divested by AOL and later Yahoo. The ads stuff did ultimately have a shelf life as the industry consolidated more on Google and Facebook but that was many years away from 2014. Mail and search were eventually merged into their yahoo counterparts post merger. People at AOL realized how the brand was that of a "wow you still exist" so were pretty good at not putting it too intrusively on new or acquired products. Good for those products, bad for the chances of revitalizing the brand. One of the interesting things post-merger with Yahoo was how much Yahoo people had not adopted the same attitude about their own brand.
- jakeasmith 16d agoOh cool. Thanks, dude! Feel free to send a message to say hi :)
- Codefrontier 17d agoLove you kept it alive this long
- hdjrudni 17d agoIt hasn't been updated in 11 years. Not sure I'd call that "keeping it alive".
- Sander_Marechal 17d agoThere is nothing as permanent as a temporary fix that works.
- chistev 16d agoNothing is more permanent than a temporary solution.
- KellyCriterion 16d ago"it was written by that guy 5 years ago,but he left; so nobody is in charge and nobody understands it anymore, but it still works perfectly and we do not need any upgrades" :-))
- goodmythical 16d ago"Okay, that's just about the end of your training, any quest-OH, Don't forget, you can never ever turn off the light in the storage closet! It is cursed and the company cannot function while the switch is off. Yes I know there's no lightbulb. No we do not know why. If we knew why it wouldn't be that way."
- CommieBobDole 16d ago"No, we don't know why the two positions of the switch are labeled "magic" and "more magic".
- KellyCriterion 15d agoOnce I worked at a company in a "historic building": In some of the rooms, the wallplugs were connected to the switch for the ceiling lightbulb and you had to draw/rotate the switch into the correct direction, to have energy on the wallplugs. People always complained that something must be broken in these rooms,since they do not have alectricity the whole day on all the wallplugs :-D :-D
- tpmoney 15d ago
- laruss5 17d agoFor a package with that kind of install base, is there a final release that prints the migration options in a deprecation notice? People will find it years from now through old Stack Overflow answers.
- TimWolla 17d agoThe package is marked as abandoned on Packagist [1] > This package is abandoned and no longer maintained. No replacement package was suggested. Both adding it as a dependency using composer and installing it from a lockfile results in: $ composer require jakeasmith/http_build_url […] Package jakeasmith/http_build_url is abandoned, you should avoid using it. No replacement was suggested. […] $ rm -r vendor/ $ composer install […] - Installing jakeasmith/http_build_url (1.0.2): Extracting archive Package jakeasmith/http_build_url is abandoned, you should avoid using it. No replacement was suggested. […] [1] https://packagist.org/packages/jakeasmith/http_build_url https://packagist.org/packages/jakeasmith/http_build_url
- ethanprk 17d ago[flagged]
- crumb1e 16d agoReading this made me really nostalgic. I cut my teeth in web/software dev in the Laravel 5.x days, and it's quite jarring comparing the day-to-day we have now with back then!
- deleted 16d ago[deleted]
- AltruisticGapHN 16d agoShould the repo be archived? I rarely see people use that feature yet tons of repos on Github are essentially dead.
- jamietanna 16d ago+1 on this - Jake's done the best thing with deprecating the package (which shows up locally in tooling and will also be surfaced by static analysis tooling (ie security vendors) based on that, but also archiving the repo indicates it to anyone who lands on the repo
- jakeasmith 16d agoDidn't know this was a thing. I'll look into it.
- edg5000 16d agoCrazy that the bug went unnoticed. So many sites must have been broken by the "a" bug.
- dspillett 16d agoIt only kicks in in the presence of a trailing / - perhaps this is rare where the function is commonly used.
- kijin 16d agoConsidering that every WordPress permalink has a trailing slash by default, and given that WordPress is sort of a big deal in PHP, I'm surprised that it took so long to find that bug.
- samayashar 16d agoThanks for pointing this out. I used PHP for one of my professional projects and never came through this - maybe because the library was not a part of our codebase. This article will be very useful for people who might shift back to older PHP versions for compatibility and face it.
- algoth1 16d agoAre you from Nebraska?
- kstrauser 16d agoI am, or was. Once, while living there, I wrote a little C program to read a Visual FoxPro database file and write out PostgreSQL commands to load the data. It was for my employer at the time. We needed it for a migration. And then, a year later, I got invited to a PostgreSQL convention in Brazil where it was one of the tools being quasi-formally recommended to help migrate the country off of VFP. The world can feel awfully freaking small sometimes.
- gitowiec 16d agoOmg, PHP... I ditched this language 7 years ago, because I was fed up with the context switching (fullstack webdev). In the beginning I really was enjoying the gentle slope of learning. I could do a lot without knowing what classes, objects and types are. And I am grateful for this, because thanks to it, now I am here where I can do much more powerful things knowing classes, objects, types and paradigms
- alt227 16d agoPHP kept on getting professional attention and development, and so now it also has all those things you mentioned.
- hiccuphippo 16d agoYes, but also Wordpress still exists and keeps the old ways of doing things.
- alt227 15d agoSaying that a certain project exists that does not use newer features of a language does not detract from the fact that the language itself is much more featureful. Im sure I could find popular projects in every language in the world which only uses old library functions and hasnt been updated. I would hazzard a guess that as node changes so frequently, there are untold amounts of projects still using old inefficient methods compared to what is available in the latest version
- shevy-java 16d ago[flagged]
- hk__2 16d ago> Along with the numbers, there were a handful of GitHub issues, including one where joining a path onto a URL with a trailing slash strips every letter “a” out of the path.
- j4kp07 16d ago[dead]
- iliasaberkane 16d ago[dead]
- alpha_trion 16d ago12 years is a pretty good run for a temporary fix!
- staplung 16d agoBy Hyrum's Law and the fact that there are 20M installs, we can infer that somewhere, some nitwit is probably using this bug as a handy function for removing 'a's from a string. https://www.hyrumslaw.com/ https://www.hyrumslaw.com/ https://xkcd.com/1172/ https://xkcd.com/1172/
- racl101 16d agoI love these kinds of stories.
- swiftcoder 16d ago> Under a comment that reads // Workaround for trailing slashes, my code tacks an “a” onto the path so there’s always a last segment to cut off, then cuts it off with a find-and-replace. When the path ends in a slash, that last segment is just the “a”, and the find-and-replace takes every other “a” in the path with it. This is top-tier. left-pad levels of "we should just implement trivial functions in our own codebases" (I do not mean that as a knock on the author - it solved his use case just fine. Everyone who took a dependency on it afterward though...)
- kstrauser 16d agoHeh, right? Author: Ugh, this is ugly, but it fixes the specific problem I’m having so I can go on and work on other things. Author, later: What do you mean, you’re all using this?
- jakeasmith 16d agohahaha yes, this exactly
- zackmorris 16d agoPHP did extensions and PECL modules wrong, due to its roots as a web server language. With managed hosting, often PHP doesn't offer what we might think of as basic functionality, since the admin didn't install/enable it. So it makes sense that these little one-off packages exist to route around snafus. It's still my favorite language though, since it comes closest to shell language but with C-style syntax (other than maybe Perl, which is a write-only language and hard to read, which unfortunately inspired Ruby to inherit some anti-patterns). I often dream about writing a modern hacker language that combines the best of everything like functional programming, higher-order methods, const by default, parallelism, sync blocking rather than async nonblocking concurrency, etc. It would also undo the pass-by-reference footguns added by PHP 5+ and return to the pass-by-value copy-on-write style of arrays. That's why I really can't endorse attempts like Hack which just introduce a new standard with its own problems. The insight being that LLMs work around the limitations of mainstream languages and frameworks, rather than challenging assumptions from first principles and building better foundations.
- iwontberude 16d ago[dead]
- hackthemack 16d agoSame. pass-by-value copy-on-write. I always find other languages strange that they do not have this.
- tcdent 16d agoI don't think I quite valued the Open Source PHP ecosystem at the time as much as I should have. I have a project that still grabs a ton of installs for some reason (3+ million to date and apparently growing) which is way beyond anything I would have expected. https://packagist.org/packages/tcdent/php-restclient/stats https://packagist.org/packages/tcdent/php-restclient/stats
- KellyCriterion 16d agoCurious: How big is the risk that abandoned extension/fixes turn into a security problem soon in these AI days?
- bdcravens 16d agoIn 2009, I started a project, was given a CSV, and in testing the import I created a quick table called "{businessDomain}Temp". Yes, that table is still there, still has the same name, and is load bearing (not in the LLM meme sense, but the business depends on it). Yes, I'm been promising myself I'll fix it one day for just as long.
- ivo93 16d ago[flagged]
- yaniv_codpal 16d ago[flagged]