• Object@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    30
    ·
    3 days ago

    found 7745962577 vulnerabilities (7653345675 low, 91726393 medium, 817263 high, 73246 critical)

      • SuperSpruce@lemmy.zip
        link
        fedilink
        arrow-up
        8
        ·
        3 days ago

        Vulnerabilities are flaws in software that may allow an attacker to gain control of or eavesdrop a system.

        They are categorized into low, medium, and high severities based on how easy it is to exploit the vulnerability and how much damage a successful attack utilizing that vulnerability would do.

        • Contentedness@lemmy.nz
          link
          fedilink
          arrow-up
          5
          ·
          3 days ago

          I’ll add that you get these vulnerability reports whenever you install a new module into a node project, though the example here is extreme.

  • ddplf@szmer.infoBanned from community
    link
    fedilink
    arrow-up
    9
    arrow-down
    8
    ·
    edit-2
    3 days ago

    Which is of very little importance in most cases, because modern bundlers incorporate treeshaking in order to filter out all the unused code when you’re building a production application

    Edit: okay well appearently that’s controversial for some reason

    • BlueMagma@sh.itjust.works
      link
      fedilink
      arrow-up
      6
      ·
      3 days ago

      I didn’t know about treeshaking (still unsure what it is exactly since I’m not a js Dev), but I’m guessing it still takes up Gigs of space in the project folder of every Devs PC, duplicated for each project.

      • ddplf@szmer.infoBanned from community
        link
        fedilink
        arrow-up
        4
        ·
        2 days ago

        It does take a lot of space for devs, but personally I find that absolutely irrelevant, because it’s your end user’s experience that really matters, and - as a dev - you are most likely to have a much better rig and internet connection than your average Joe.

        • jim3692@discuss.online
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          2 days ago

          Sure, in many cases the dev’s computer is powerful enough to handle that.

          However:

          • The more the dependencies, the more likely it is to pull-off a supply chain attack. Any of those thousands modules can be compromised and infect either the user or the developer.
          • Not all computers are optimized for working with so many tiny files. Have you ever worked in a company that uses McAfee Antivirus? Even Defender can be a massive performance hit in some cases.
          • ddplf@szmer.infoBanned from community
            link
            fedilink
            arrow-up
            2
            ·
            2 days ago

            I have to say that I may be a bit ignorant, because I’m mostly engaged in greenfield projects with very tiny devteams and I always keep my dependencies count low as possible

            Thank you for pointing this out, that’s very valuable to keep in mind

      • Pieisawesome@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 days ago

        Tree shaking is essentially reducing the amount of included code to only the stuff being used.

        Let’s say you have a JAR, DLL, or whatever with 5 functions.

        Your application calls function A which also calls function B of the DLL/jar.

        Tree shaking says “hmm, if I follow the code execution path, I only need 2/5 functions from the DLL/jar” and discards the remaining 3/5 functions.

        This significantly reduces the bundle size (the bundle is what is sent to the browser).

      • dazeous@lemmy.ml
        link
        fedilink
        arrow-up
        3
        ·
        3 days ago

        Some use ‘pnpm’ package manager, alternative to default, where the packages are downloaded once to a central location, and per project directory, it links to the original location so files aren’t duplicated saving space

    • dazeous@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      3 days ago

      node_modules might take a lot of space on a dev machine, but as op said, only the files used are packed into web artifacts that are deployed.

      So 12gbs can end up as 10mb, arbitrary number to highlight significance of tree shaking.