←back to thread

295 points todsacerdoti | 1 comments | | HN request time: 0s | source
Show context
Levitating ◴[] No.45948952[source]
I am sure I am not the only one who thinks these micro-dependencies are worthless anyway. You'd be better off just listing the functions in a markdown file for people to copy over than ship an entire package for it.

This isn't "small" open source, "small" would be something you put together in a week or weekend. These are like "micro" projects, where more work goes into actually publishing and maintaining the repository than actually writing the library.

I like the approach C sometimes takes, with the "tiny header file" type of libraries. Though I guess that also stems from the lack of a central build system.

replies(4): >>45950899 #>>45950912 #>>45953455 #>>45955108 #
eviks ◴[] No.45950899[source]
What's your copy& paste solution to security updates?
replies(2): >>45952213 #>>45952228 #
immibis ◴[] No.45952228[source]
Does left-pad have security updates? You may as well ask what's the security update solution for Stack Overflow answers.
replies(1): >>46003542 #
1. eviks ◴[] No.46003542[source]
Does every single small package have a guaranteed security profile of left-pad?