Live data from Hacker News

How one developer just broke Node, Babel and thousands of projects

theregister.co.uk

11–15 of 15 posts

Re: How one developer just broke Node, Babel and thousands of projects

#13
I've had problems with NPM where a deep dependency was wrong for my system, and was tempted to solve it in the following way: fix the deep dependency in a cloned-project, and create github clones of every dependency in the chain that refers to it using the new package address in their package.json. That sounded wrong so I didn't do it.

One mechanism that could fix that problem, and the left-pad problem is to allow defining a package substitute in your root package.json file. Then you could swap out the dependencies of your dependencies.

packageReplace : [{source_name: 'left-pad', source_version: '1.0.1', target: 'https://github.com/foo/bar' }]

...something like that

Re: How one developer just broke Node, Babel and thousands of projects

#15
post #8

I completely agree with the developer here, I also think npm crossed the line by republishing the module.

Yeah, though I'm curious what the proper solution would have been. It seems to me that once published to NPM there should be some process for deprecating a module that is then "unpublished"... rather than just breaking every module that uses it as a dependency instantly. They could spawn automatic emails to all dependent module owners about the hard deprecation and give them 7-30 days to replace the module before it'…

I think it is also a reflection on the state of the node ecosystem, including an external dependency for a few lines of simple code. Note this isn't only nodes issue, ruby has a similar issue with gems.
Post reply on HN