news.volyx.in

A one-line package broke `npm create-react-app` (github.com)

599 points by tessela · 2356 days ago · 459 comments on HN

Article summary

A one-line package called `is-promise` broke `npm create-react-app` due to an invalid 'exports' main target defined in its package config. The issue arose when using Node version 13.12.0, while version 2.1.0 of the package still worked fine. The error occurred because the package's test matrix did not cover the latest Node versions. The package has since been updated to fix the issue.

Main themes

  • npm package issues
  • JavaScript ecosystem problems
  • dependency management
  • Deno and alternative runtimes
  • regression testing
  • Python vs JavaScript
  • CI/CD pipelines
  • package security

What commenters say

  • The JavaScript ecosystem has a problem with dependencies and package management, leading to frequent breakages and security issues.
  • Some developers believe that Deno, a new runtime, may help alleviate these issues, while others are skeptical.
  • Regression suites and dependency pinning can help prevent such breakages, but are not always used.
  • The use of many dependencies in JavaScript projects is seen as a necessary evil by some, while others argue that it is a sign of poor design.
  • Python is seen as a more robust alternative to JavaScript by some, with fewer dependencies and better packaging, but others disagree.
  • The importance of testing and CI/CD pipelines is emphasized by some commenters, who argue that they can help catch errors before they cause problems.
  • Some developers feel that the JavaScript ecosystem is inherently flawed due to its emphasis on extensibility and flexibility over robustness and security.