I will pay you cash to delete your NPM module
drewdevault.com
drewdevault.com
In the nightmare hellscape of mainstream languages like JS and Python on the other hand, it's common practice for projects to have dozens, hundreds, even thousands of dependencies -- and that's without even taking into consideration the dependencies of those dependencies, and then furthermore whether those dependencies are pinned. But since this is JS or Python, the dependencies are almost certainly pinned, which causes even more headaches that makes packaging software in a reproducible and auditable way practically impossible for certain languages. And since there's no stable spec and usually only one implementation, no one thinks about portability at all either; you get what you get and if you're lucky it's not impossible to port to an OS other than Linux. This problem of portability is only compounded on by the potentially massive amount of dependencies some of these projects will have. I don't understand how anyone lives like this but people really need to start being more responsible with the code they put out into the world.
Or one could just take up Drew's satirical software eco-terrorism as the only possible viable praxis for abolishing the present state of software development...
I wouldn't be surprised if the software development contracts outright blacklist aforementioned programming languages and ecosystems notorious for senseless dependencies in the name of 'Getting things done'.
The frontend javascript ecosystem can only be described as deranged. If anything, it's a miracle that malicious packages don't happen more often than they do. One of my side projects has over 1000 indirect dependencies (according to ls -l .yarn/cache | wc -l), and it's not a project I'd consider especially fancy. Alacritty has 200 indirect dependencies, and as far as I've seen that's the upper bound for most rust projects. For NPM, it's the lower bound.
Running yarn in firejail/bwrap helps, but it's not easy to set up and sandbox escapes can happen (same with docker).
[1] https://github.com/tarruda/has/pull/16 [2] https://github.com/bearror/oletus
Base64/hex/binary conversion, type checking, DOM access shortcuts, etc. etc.
var iframe = document.createElement('frame');
document.body.appendChild(iframe);
var value = iframe.contentWindow.Array();
value.constructor === Array // false
value instanceof Array // false
value instanceof iframe.contentWindow.Array // true
Stringifying the constructor works even for cross-frame values: value.constructor.toString() === Array.toString() // true
These days though, `Array.isArray` is the right thing to do, available since roughly 2010.The only special thing about JavaScript is that after 25+ years the standard library is still grossly inadequate.
I've some modules I built just because it looks cool to have npm modules with N downloads on your CV. I don't really need that now.
No idea who the hell use them but I very rarely receive a PR or issues. They're basically unmaintained.
It's a bit like having 200+ projects on GitHub and a lot of green squares, people are just going to look at the whole thing without digging much further.
I got some work leads just from people telling me "Yo, I've seen your GitHub, wanna work?"
[1] https://drewdevault.com/2021/11/16/Cash-for-leftpad.html#con...
This will also create a new opportunity for someone else to...recreate the module, and chances are that it will likely include some malicious or even more broken code.
If you want to "improve" the situation, you update the module with code that triggers an exit with a warning message. That will fix the problem.
Because if we start there, we might actually make this work.
(I know program comparison is akin to the halting-problem, but for simple templates it should work).
also, during early nodejs phase (2012~14) such bots existed, but were considered generally annoying and not welcomed by the community
What about people who value helping others more than the money? and Disagree about the value of the "help" an `npm` package actually is? I like this idea but I can see there's room for disagreement.
Say there's a particularly problematic package... are you justified in hiring a bounty coder to replace it? How about a bounty hunter to eliminate its current maintainer? Is the action more moral if many people gang up to fund and direct the bounties' goals?
Telling people their "gifts to the world" shouldn't exist isn't likely to make you popular. The dumpster fire of NPM being a public hazard is hard to argue against too, so its a hard one.
What software package are you willing to hire bounty hunters to hunt people over? I personally don't care for PHP; but I'm not that emotional over it.
There are constructive solutions to this problem. The solutions do not entail breaking literally millions of builds and suggesting that a developer should torch their reputation for, what, $710 (LOL, give me a break, Drew).
What we have here is performative attention-seeking, known clinically as "maladaptive coping." It's a shame to see this stuff day after day voted up to the HN homepage.
“the use of humor, irony, exaggeration, or ridicule to expose and criticize people's stupidity or vices, particularly in the context of contemporary politics and other topical issues.”
Where’s the humor? Where’s the irony?
What is he “satirizing”?
He’s trolling and calling it “satire.”