If only we could get rid of dynamically called code and instead could evaluate which code paths the code actually can call, then we'd be able to throw out about 90% of the contents of libraries, since most of the time noone actually uses all of that functionality.
Doing that with separate scripts is another approach, but it feels like the problem should be solved at its root.
In many cases Clang and GCC compiler can easily understand loops, and even reduce them to constant time.
https://docs.microsoft.com/en-us/dotnet/core/deploying/trimm...
I don't understand why people are so willing to depend on these crazy dependency trees, where most of the code was written by people you don't even know the names of.
These managers dont replace the chain of trust, if you dont trust a dependecy and the developer behind dont install it.
"And it's impractical to audit them all." I dont use NPM but for composer.json: https://github.com/fabpot/local-php-security-checker
I agree, composer is not perfect, but before it was worse.
{
"require": {
"google/apiclient": "^2.10"
},
"scripts": {
"pre-autoload-dump": "Google\\Task\\Composer::cleanup"
},
"extra": {
"google/apiclient-services": [
]
}
}
=> vendor folder size: 6MB, 1012 Files