Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

yeah this part is pretty bad

you can get lucky and reach a nirvana state where all your dependencies function well in a new project, but 6 months later its a disaster like ah you need to upgrade node, but ah your transpiler requires the older version of node, but ah the semantic versioning was not followed by your type definition addendum library and now there were autoupdated breaking changes, ah your project only worked with a locked package file and if you re-install any package the wrong way everything breaks in incomprehensible ways!

I know my way around it though, so yay big bucks and quick deployment of greenfield projects



I know this isn’t realistic for many many scenarios, but if you can help it there is a sweet spot where you dedicate ~30 minutes to merge weekly dependabot updates and you don’t run into this problem.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: