Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nicksnyder
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
nicksnyder
8y ago
Sourcegraph ( https://sourcegraph.com ) | Software Engineer | San Francisco, CA or REMOTE Sourcegraph is building a better, smarter foundation for software development to help you answer questions about your code. Our code search
32.
▲
by
nicksnyder
8y ago
Sourcegraph ( https://sourcegraph.com ) | Software Engineer | San Francisco, CA or REMOTE Sourcegraph is building a better, smarter foundation for software development. Our code search allows you to instantly search across all of
33.
▲
by
nicksnyder
8y ago
Sourcegraph ( https://sourcegraph.com ) | Software Engineer | San Francisco, CA or REMOTE Sourcegraph is building a better, smarter foundation for software development. Our code search allows you to instantly search across all of
34.
▲
by
nicksnyder
8y ago
Sourcegraph ( https://sourcegraph.com ) | Software Engineer | San Francisco, CA or REMOTE Sourcegraph is building a better, smarter foundation for software development. Our code search allows you to instantly search across all of
35.
▲
by
nicksnyder
8y ago
Sourcegraph ( https://sourcegraph.com ) | Software Engineer | San Francisco, CA or REMOTE Sourcegraph is building tools that software developers love and use on a daily basis. Our code search allows you to instantly search across
36.
▲
by
nicksnyder
8y ago
Sourcegraph ( https://sourcegraph.com ) | Software Engineer | San Francisco, CA or REMOTE Sourcegraph is building tools that software developers love and use on a daily basis. Code search allows you to instantly search across all
37.
▲
by
nicksnyder
8y ago
> As the writer of an application I like the power of short-cutting that path if needed for an important update of a transitive dependency by simply telling my package manager to update the lockfile, vs having to wait for the update to t
38.
▲
by
nicksnyder
8y ago
This pain isn’t really about Renovate Bot. You can pretend that it doesn’t exist or that your project isn’t using it. I should still be able to update a single dependency without updating unrelated things.
39.
▲
by
nicksnyder
8y ago
Rephrased: npm’s design incentivizes projects to assume “patch versions are safer to update than minor versions are safer to update than major versions” to avoid dependency duplication. Such incentives do not exist with MVS because all that
40.
▲
by
nicksnyder
8y ago
You can argue about what is more important for your project, but the worst part is that npm doesn't give project owners to decide otherwise. As kjksf already stated, patch versions can introduce security vulnerabilities too.
41.
▲
by
nicksnyder
8y ago
NPM specially assumes that "patch versions are safer to update than minor or major version". MVS doesn't make that assumption. > it seems to stem from bad design decisions made by NPM authors Yep. > doesn't have a
42.
▲
by
nicksnyder
8y ago
It doesn't happen automatically if you don't want it to (and it didn't happen automatically in this case). The value here is that it notifies you if an update is available (by opening a pull request), automatically tests the
43.
▲
by
nicksnyder
8y ago
It isn't an argument, it is just a fact. All else equal, it is a nice fact.
44.
▲
by
nicksnyder
8y ago
Renovate Bot didn't do anything special. It ran exactly the same npm command that I would have run on the command line (update the single dependency), which would have produced the exact same result.
45.
▲
by
nicksnyder
8y ago
Sourcegraph ( https://sourcegraph.com ) | Software Engineer | San Francisco, CA or REMOTE Sourcegraph is building tools that make software developers love and use on a daily basis. Code search allows you to instantly search across
46.
▲
by
nicksnyder
8y ago
Sourcegraph ( https://sourcegraph.com ) | Software Engineer | San Francisco, CA | ONSITE or REMOTE Sourcegraph is building tools that make software developers more productive on a daily basis. Code search allows you to instantly s