logoalt Hacker News

xnorswapyesterday at 4:54 PM2 repliesview on HN

Perhaps it's time to organize a curated "stable" stream for npm packages.

If I want more stability for my OS I can choose Debian-stable rather than Ubuntu-nightly.

But for npm, there doesn't seem to be the same choice available. Either I sign up to the fire-hose or I don't.

I can choose to only upgrade once a month, but there's a chance I'm still getting a package that dropped 5 minutes before.


Replies

Etheryteyesterday at 6:17 PM

Upgrading once a month is insane at any rate, I could see the point in upgrading maybe once a year. For stable projects, you're very much fine upgrading only when there's a vulnerability or you need something from a newer release. Upgrade when you actually need to and use stable versions that have been out for a while, no need to hamster wheel it.

show 1 reply
philipwhiukyesterday at 5:21 PM

pnpm

   minimumReleaseAge: 43200