It's also exactly what the websites you visit do. ;)
It's also exactly what the websites you visit do. ;)
This is definitely false. For all the problems with the NPM registry and the Node dependency situation, an NPM package at a specific version is not just at the whims of whatever happens to be at the other end of a URL at any given moment it's requested. This is a huge vulnerability that the Node/NPM world does not currently have.
Deno does have lockfiles: https://deno.land/manual/linking_to_external_code/integrity_...
I prefer imports from URLs. And I loathe npm. I get why people would disagree though.
Always commit your lock files people
I don’t know the state of the art anymore, but I’m sure they have ways to make it easy to vendor deps in the repo.
I'm not sure how this works in detail here, but at least in NPM you got a chance to download packages, inspect them and fix the versions if so desired. Importantly, this gave you control over your transitive dependencies as well.
This seems more like the curl | bash school of package management.
Edit: This is explained in more detail at https://deno.land/manual/linking_to_external_code and indeed seems a lot more sane.
> It's also exactly what the websites you visit do. ;)
Well yes, and it causes huge problems there already - see the whole mess we have with trackers and page bloat.
Even with all NPMs flaws, I do feel this is a bit of throwing the baby out with the bath water. Time will tell.
That's not true here. If I'm running a web server I'm going to need to give the app permission to read the files being served and access to the database. That something that never happens in the browser.