The most popular markdown parser on npm hasn't seen a release in 7 years, and the second most popular markdown parser emits an unclosed <em> whenever you use *emphasis* syntax on any line other than the last line of a paragraph.
-
Show this thread
-
I'm on day two of a completely normal "update all of our dependencies" cycle and it feels like it will never end. Really making me wish I weren't married to the Node+npm ecosystem. No other ecosystem that I've worked in has been like this.
7 replies 15 retweets 98 likesShow this thread -
Apparently those popularity rankings that I quoted were wrong, because sorting by "popularity" in NPM doesn't seem to sort by popularity.
3 replies 1 retweet 59 likesShow this thread -
Does anyone except me care about any of this? It feels like everyone else is content to have everything break at random on a daily basis, then often stay broken for months or sometimes forever. (This is an actual question; I don't mean it dismissively.)
34 replies 2 retweets 130 likesShow this thread -
Replying to @garybernhardt
some interesting and worrying signal that I've got as a result of publishing some npm security releases recently is that there's a significant number of users for whom it's not clear how to upgrade dependencies, which pushes them towards extremely brittle release management
2 replies 0 retweets 3 likes -
Replying to @mountain_ghosts @garybernhardt
as in "how do I upgrade an indirect dep" does not have an unambiguous clear universally known answer
1 reply 0 retweets 1 like -
Replying to @mountain_ghosts
Oh I don't even know *an* answer to that, let alone a good answer. I've always done `npu -u && npm i`, but today I wondered "what happens if I then `rm package-lock.json && npm i`, and that resulted in a different lock file. Literally not even as a guess as to why.
1 reply 0 retweets 1 like
I've 100% resorted to manually editing lockfiles for transitive dependencies before
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.