Reply to post: Re: The problem is easy to express

When one open-source package riddled with vulns pulls in dozens of others, what's a dev to do?

DemeterLast
Mushroom

Re: The problem is easy to express

It doesn't help that all of these frameworks, libraries, toolkits, etc. all put a gigantic Smiley Face all over their web site and documentation. "FooLib makes YOUR_PROBLEM_HERE so easy! And it's better than BarLib!"

Then they demonstrate how easy it is to do something that's stupidly easy already.

Unremarked upon is the 12.75GB of third-party libraries their framework, library, toolkit, etc. pull in as dependencies, which you barely even see scroll past when you run their recommended Yarn/npm/Composer/pip/etc. one liner to grab all that stuff. Or, they just tell you to download and use their stupid freaking Docker recipe.

"It's so easy!" No it isn't. It never is. And your shiny happy people attitude is giving impressionable young developers hope and optimism, when what they should be feeling is despair and cynicism. This modern drive towards acceptance and unity and inclusiveness is killing development. Developers should be angry, bitter, hateful towards users, and above all deeply skeptical of anything new. Security becomes super easy when nobody is allowed to do anything.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon