Left-pad shows how fragile small dependencies are
Summary
The removal of a tiny npm package breaks numerous builds and triggers a debate about dependencies and registry governance. Left-pad pads strings on the left. The incident occurred in March 2016.
Ideas
- Many packages relied on eleven simple lines of JavaScript.
- Removing one version made dependency resolution impossible.
- Transitive dependencies hid the affected function from applications.
- npm republished the package to restore other people's builds.
Insights
- Tiny components can become system-critical through their spread.
- Convenient reuse shifts maintenance and availability risks.
- Immutable artefacts need clear rules for removal and ownership.
Facts
- Numerous JavaScript projects temporarily could not be built.
Recommendations
- Mirror critical packages and use lock files.
- Check transitive dependencies for necessity and maintainer risk.
References
Links to the original source and the Web Archive open in a new tab.