Hacker News new | ask | show | jobs
by TiredOfLife 27 days ago
Also Rubygems, Packagist, PyPi
2 comments

pip install pulls in what I've listed in my package list, plus their dependencies which are at most 2 levels deep. The dependency's dependencies are reviewable.

npm install pulls in my dependencies plus god knows what else at god knows how many levels. 500MB of dependencies? The dependency's dependecies are not reviewable.

I wish people would stop trying to compare NPM to PyPi and others. NPM is an unfixable disaster because of the entire mindset and ecosystem around JavaScript.

Somebody posted today about getting 3-4 pip top-level deps, and they brought in around 400 packages. That's not exactly that different.
What's the worst hack to affect users of rubygems?
DHH, of course.