What is the best source on these topics?
I’m not being cheeky here. I’m genuinely interested, because I see these terms thrown around a lot without reference.
With regards to design patterns I would recommend the Gang of Four book on the subject. It's old (to the point where it makes me feel young) but still relevant as most of the patterns you'll see in the wild will be described there or be slight variations.
For security I've heard people describe the OWASP Top Ten as the software equivalent of the Ten Commandments. It's been around for almost two decades and is also still very much relevant today, perhaps even more so going by the comment you replied to.
I don't know Rect (besides implementing the todo list they have in their frontpage), but I can learn in a few weeks to become proficient on it. Don't hire "React developers", hire "good developers".
On the backend at the Principal level, I’ve see the opposite thankfully. Most companies don’t seem to care about the specifics—the current buzzword with is that they care that I can design “web scale” systems (regardless of whether the company actually has web scale problems—but that’s a different problem).
Indeed. So then they'll go ahead and design "web scale" solutions to non-existent problems. I quote web scale since in the majority of the cases I've seen, the solutions don't actually seem particularly capable of handling massive scale but since they don't need to, it never gets tested.
Worked with one company with this ginormous logging and analytics pipeline which consumed most of the AWS budget, but the actual data flowing through it amounted to a handful of million entries per year. Yes year. At that scale, the wise solution is grep and awk on a $5 VM.
Solve the problems you actually have and the ones you can project to having in six months. Don't solve the problems you wish you'll have in ten years.
In general that is not necessarily bad, it can be a good thing.
> they keep learning framework and library without caring about software principle, architectural or design patterns or security best practice
My guess here is that it is a way to get into more interviews. Many job openings today lists a ton of libraries and frameworks that you should have experience with, thus the market reacts(!) accordingly.
I don't really know whose fault it is, but I can tell you from experience that if you present yourself as having good -even excellent- experience and knowledge of the principles, the practices, and the patterns, and having similar experience with $similarFrameworkA and $similarFrameworkB, but not with $thisParticularFramework, then "you're not quite what we're looking for". And the opposite is common too. If you do have a couple of years experience with $thisParticularFramework you're good to go. It doesn't matter whether you don't know how to do anything else outside of that.
This is something people don't often want to admit, or sometimes even discuss. I'd guess it may be related in some way to another rarely admitted fact about the industry: There is a lot of wasted effort and resources. Particularly in certain types of projects and companies, the overall productivity is extremely low.
If I compare that to my own experience learning web dev in the early 2000s on my own. Make a html file with some css and ftp it up to a server. First version done. Add some JS, some PHP, then a database. Eventually move from vanilla code to different frameworks and languages, move from a Linux box to some cloud services, slowly start working with more complex systems and different paradigms. The whole process was very iterative and I feel I have gotten a lot of transferable knowledge on the way.
Of course this is perfectly possible to do these days as well, but it is not what I see happening or being widely encouraged in communities or fostered within companies. It seems more about run this and that generator script, click this button to spin up the managed services to run it on. See, it is so easy, so no problem. Creating hundreds of dependencies and layers of abstraction with practically no idea what they do. I had people wanting to learn programming from zero asking me to help with issues with their docker setup before having written a nested for loop.
I'm definitely not against those "modern" tools, they can be an awesome productivity boost if used well in the right context, but I can't help but often feel reminded of the good old Jurassic Park quote when it comes to tech stack decision making: "Your scientists were so preoccupied with whether they could, they didn't stop to think if they should"
If you only need a view lib: uhtml, lit-html