Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
segphault
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
segphault
8y ago
VuePress pulls in nearly a thousand transitive dependencies. In light of recent security incidents[0][1] and the relative ubiquity of poor security practices[2] in the npm ecosystem, that seems like an unacceptably large attack surface. I d
92.
▲
by
segphault
8y ago
I really like the idea of a non-intrusive analytics system that just shows you useful aggregate traffic data while maintaining the privacy of your site's visitors. I experimented with using GoAccess ( https://goaccess.io ) on
93.
▲
by
segphault
8y ago
Off topic, but the totally pointless animated gifs in this article are distracting and made it painful to read. I don't understand why they felt the need to make an article about a serious topic look like a teenager's tumblr post.
94.
▲
by
segphault
8y ago
It's an electron wrapper around the official Evernote web app, but with some color themes. Why do I want to use this instead of Evernote's high-performance native desktop client?
95.
▲
by
segphault
8y ago
I really like the idea of declarative and machine-readable validation and API descriptions, but JSON schema is often pretty frustrating to work with in practice. Building a compliant implementation is quite difficult. The $ref resolution, a
96.
▲
by
segphault
8y ago
Also worth checking out Kni, an authoring language inspired by Ink but written in JavaScript, ideal for bringing this kind of content to the web: https://github.com/kriskowal/kni
97.
▲
by
segphault
8y ago
Integrating nsp is a very welcome move. It's heartening to see npm taking the security issue seriously and taking steps to start addressing the problem. That said, the problem remains largely cultural rather than technical. The communi
98.
▲
by
segphault
9y ago
You should consider using the window.history APIs to make it so that navigating your blog doesn't break the back button.
99.
▲
by
segphault
9y ago
What I suspect is going to happen is that frontend people will just shrug and adopt the .mjs extension. Browsers don't care what extension you use as long as the mime type sent by the server indicates that the file is javascript.
100.
▲
by
segphault
9y ago
> I've heard it said before that you're responsible for every line of code you ship to your users. This is a great way of thinking about it. I wish that more people took it to heart when choosing third-party dependencies to ado
101.
▲
by
segphault
9y ago
Santana Row is fantastic, I can imagine that it'd be a great place to live. That kind of mixed-use development is something that really ought to be more ubiquitous. It's worth noting that there are even companies, like Splunk, th
102.
▲
by
segphault
9y ago
And you don't care if a malicious party compromises the development machine on which it runs? I can think of a whole lot of really damaging things that somebody could do running arbitrary JavaScript code with user-level privileges on t
103.
▲
by
segphault
9y ago
It literally just removes a line from the package.json file of one of the sub-dependencies: https://github.com/babel/babel/pull/5484 It's crazy to me that a package that is downloaded from npm over 4 mil
104.
▲
by
segphault
9y ago
689 packages is enormous surface area for a leftpad-like (or worse) failure. Given that nobody is auditing those packages and many of the people who maintain them aren't adhering to best security practices[1], I don't think taking
105.
▲
by
segphault
9y ago
With transitive dependencies, the total install footprint for this is 689 packages weighing in at 77MB. This isn't reducing complexity, it's just taking all the junk you'd normally have in your bloated boilerplate and putting
106.
▲
by
segphault
9y ago
This pulls in over 200 dependencies, with a total weight of 37MB. I'll pass.
107.
▲
Using TypeScript's type checking in vanilla JavaScript without transpiling
(seg.phault.net)
1 points
by
segphault
9y ago
|
1 comments
108.
▲
by
segphault
9y ago
What this amounts to is an attempt to solve the challenges of monetizing open source software by no longer writing open source software. The encumbrances that this license places on the downstream modification and redistribution of code lar
109.
▲
by
segphault
9y ago
Wait, what? The official React wrapper for Elements is on GitHub: https://github.com/stripe/react-stripe-elements
110.
▲
by
segphault
9y ago
Really wish there was more momentum on adding a safe access operator. Even Ruby has that now, it's disappointing that we still don't have it in JS.
111.
▲
by
segphault
9y ago
That gets me the exact same thing. And afaik what you get from --production is the default behavior when you install a package directly from npm.
112.
▲
by
segphault
9y ago
So, I just did "npm install next react react-dom" which isn't bringing in next's development dependencies. Is there something that I'm missing?
113.
▲
by
segphault
9y ago
Interesting concept, but it seems rather heavy. Installing it from npm pulls in over 400 packages, weighing in at about 60MB.
114.
▲
by
segphault
9y ago
I'm also very interested in i3-style tiling instead of pre-configured layouts. I like being able to manage the splits more dynamically. I also really like i3's concept of hierarchies, being able to nest the splits. And being able
115.
▲
by
segphault
9y ago
Facebook is the world's largest PHP shop. Does that mean that everyone should use PHP? As it turns out, moving fast and breaking things isn't all that conducive to quality engineering[1][2]. Facebook has a massive legacy code base
116.
▲
by
segphault
9y ago
> That issue you linked to is 4 years old and is clearly a reflection of the poster being unfamiliar with React/JSX And yet the underlying issues still remain unaddressed. There aren't better ways to handle the cases raised in
117.
▲
by
segphault
9y ago
JSX is not JavaScript, it's a non-standard bastardization that will never be supported natively in browsers. Its reliance on JavaScript for flow control is so problematic[1] that people have started working around its many glaring inad
118.
▲
by
segphault
9y ago
> And the other great thing about these tools is you can add/remove them as needed. In order to get that freedom, you need to build the tooling in such a way that it aligns with the web standards, so that when the standards catch up
119.
▲
by
segphault
10y ago
There are a ton of great ideas in Vivaldi's user interface. And it's built on Chrome, so you still get all the standards and extension compatibility. They regularly add clever new features that materially improve tab management an
120.
▲
by
segphault
10y ago
The conventions they use look like BEM, which is a relatively common approach for component-based design in CSS: https://css-tricks.com/bem-101/
More ›