HN Simulatornew | past | comments | lists | submit | dhamidi's commentslogin

> So an engineer who knows your codebase and tests can sneak in malicious code/backdoors because you're high trust.

What is the alternative? Bumping a dependency in a PR and getting a LGTM can also introduce a backdoor.

That's another form of high trust: your trusting the publisher of the dependency.

High trust comes with high responsibility, which is easier to enforce when the trusted party is an individual on your team with generally aligned incentives, rather than an organization or unpaid individual on the internet serving many.


Working at Amp

We...just read the commits, and talk to each other.

We're also pretty trigger happy with the Huddle button in Slack.

Nobody on the team would go back to mandatory PRs


HTMX is great, Hypermedia and HATEOAS are great, HTML-string-templates are not great.

For some reason they are still popular.

A fun experiment is to use a JS runtime with React but render the component tree on the server onto a Writeable stream.

Very easy to understand, no useEffect footguns, great composability.


You can swipe the Termux special ribbon to the left and then get a native text input where dictation etc all work.


Cheers, you just changed my life.


Exactly, thats what makes it work with FUTO stt!


Neat trick. I had no idea.


This:

    node + npm + vitest + vite
Turns into:

    bun
That's the benefit


Throwing out a couple more benefits: bun is faster than node, dramatically so in some specific cases (websockets). Bun also has been doing a great job at building out core libs that probably don't make sense for node, such as the native inbuilt sqlite module, thereby reducing your dependency graph.

People shit on the node/npm ecosystem relentlessly for the typical inauditable deep dependency graph, and bun makes substantial improvements to that situation.

Edit: bun recently added an inbuilt api for manipulating images (resize, change formats, etc). Another good example of them adding native/faster functionality that replaces significant dependencies (in this case, likely sharp: https://www.npmjs.com/package/sharp?activeTab=versions)


I rather replace bun with deno, given that now both bun and deno are written in Rust, and Deno have even more node compatibility than bun. Deno and Node both runs on V8, while Bun runs on JSC, and Deno has a killer feature that you don't have to even run npm install to use package, you can just top-level import or await import an URL (given that you allowed it with a command prompt or bypass it competely with -A but discouraged).

I've used Deno, CucumberJS and Playwright to write E2E test suites. Zero npm install and not even deno.json or package.json


To say nothing of `bun install` being about 50 times faster than npm, and disabling most post-install hooks by default.


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: