really tired of people using the term “left-pad” in reference to http://crates.io dependency discussions, as the left-pad incident is not possible on http://crates.io by design, so it’s unclear what the term even signifies beyond “dependencies are bad”
-
Show this thread
-
Replying to @hdevalence
replace "dependencies are bad" with "dependencies add risk" and it makes sense
1 reply 0 retweets 12 likes -
Replying to @whitequark @hdevalence
reducing dependencies only reduces risk if it also reduces the number of maintainers who can publish dependencies, so it's an indirect way of arguing that fewer people with publish ability entails less risk
2 replies 0 retweets 6 likes -
Replying to @iximeow @hdevalence
indeed, that's a much more clear way to express it, and definitely preferable to alluding to it with "left-pad"
1 reply 0 retweets 6 likes -
Replying to @whitequark @iximeow
it also points to the fact that reducing the number of maintainers may just concentrate compromise risk in a small number of maintainers rather than meaningfully reducing it
2 replies 0 retweets 2 likes
While this is true, it's ultimately a numbers game. If 1000 folks can publish code I depend on, I am going to assume that by chance alone something bad will happen with one of them
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.