<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: arcatek</title><link>https://news.ycombinator.com/user?id=arcatek</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 23 Jul 2026 06:22:37 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=arcatek" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by arcatek in "Dependencies should be fetched directly from VCS"]]></title><description><![CDATA[
<p>Packages are typically different once published than they were inside their original repositories. Call it transpilation, build, compilation, packaging, etc, most popular projects require some level of support for dynamic code execution before reaching their usable state.<p>As much as I'd have liked Git to be a viable option compared to centralized registries, last couple of years demonstrated running arbitrary commands during install is too much of a risk for it to work at scale.</p>
]]></description><pubDate>Sun, 05 Jul 2026 21:28:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48798121</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=48798121</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48798121</guid></item><item><title><![CDATA[New comment by arcatek in "Upcoming breaking changes for npm v12"]]></title><description><![CDATA[
<p>As mentioned in the issue you link the problem comes from third-party packages with non-deterministic build scripts in git dependencies, or files on disk being actually different (although I guess we could at least try to normalize crlf, but as you can guess it will break <i>someone</i>).</p>
]]></description><pubDate>Wed, 10 Jun 2026 11:56:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48474971</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=48474971</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48474971</guid></item><item><title><![CDATA[New comment by arcatek in "Upcoming breaking changes for npm v12"]]></title><description><![CDATA[
<p>It's not exactly unmaintained (we merged a couple of security patches in the past years), I agree that we should have do something about it.<p>We'll be correcting this situation starting from the 6.x release, which we expect somewhere in August.</p>
]]></description><pubDate>Wed, 10 Jun 2026 11:51:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48474928</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=48474928</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48474928</guid></item><item><title><![CDATA[New comment by arcatek in "Upcoming breaking changes for npm v12"]]></title><description><![CDATA[
<p>I don't doubt that 3.x probably has worst perfs (it's almost two years old now), but just to clarify we closely track performances and Yarn and pnpm and pretty much on similar level:<p><a href="https://p.datadoghq.eu/sb/d2wdprp9uki7gfks-c562c42f4dfd0ade4885690fa719c818" rel="nofollow">https://p.datadoghq.eu/sb/d2wdprp9uki7gfks-c562c42f4dfd0ade4...</a></p>
]]></description><pubDate>Wed, 10 Jun 2026 09:58:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48473954</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=48473954</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48473954</guid></item><item><title><![CDATA[New comment by arcatek in "Upcoming breaking changes for npm v12"]]></title><description><![CDATA[
<p>Eh, easy to say. Remember how Sourceforge started shipping ads in binaries people downloaded? If you think failing was the worst scenario, you lack imagination.</p>
]]></description><pubDate>Wed, 10 Jun 2026 09:54:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=48473922</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=48473922</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48473922</guid></item><item><title><![CDATA[New comment by arcatek in "Upcoming breaking changes for npm v12"]]></title><description><![CDATA[
<p>Of course. Modern Yarn releases (4.x) are deterministic to a fault and you can rely on it to have a consistent behavior across your whole team. As for feature-wise I'd say it's a lot of small details that together add up once you grow used to them.<p>The next major release will keep pushing in that direction with both better performances and features we couldn't implement until now due to their reliance on said perfs improvements.<p>Disclaimer: I'm the Yarn lead maintainer.</p>
]]></description><pubDate>Wed, 10 Jun 2026 09:47:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48473877</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=48473877</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48473877</guid></item><item><title><![CDATA[New comment by arcatek in "Uv is fantastic, but its package management UX is a mess"]]></title><description><![CDATA[
<p>Curious how you did this; I looked into that couple of months ago but even with custom hooks the Python injection points seemed to limited due to the internal resolution cache.</p>
]]></description><pubDate>Fri, 22 May 2026 07:00:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48232877</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=48232877</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48232877</guid></item><item><title><![CDATA[New comment by arcatek in "Using coding assistance tools to revive projects you never were going to finish"]]></title><description><![CDATA[
<p>Isn't Godot a little ill-designed to work well with LLMs? for example I ended up a couple of times with incorrect tres files, and letting the llm generate IDs feel a little fragile.</p>
]]></description><pubDate>Sat, 25 Apr 2026 20:12:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47904206</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=47904206</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47904206</guid></item><item><title><![CDATA[New comment by arcatek in "Package Managers à la Carte: a formal model of dependency resolution"]]></title><description><![CDATA[
<p>It's not about the package manager, it's about the runtime. Python isn't able to support this pattern with its resolution pipeline, so package managers have to resort to do the work to dedupe versions.<p>By contrast Node.js has built-in capabilities that make this possible, so package managers are able to install multiple versions of the same package without that issue.</p>
]]></description><pubDate>Sat, 28 Feb 2026 09:23:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=47192766</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=47192766</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47192766</guid></item><item><title><![CDATA[New comment by arcatek in "Next-generation AI models"]]></title><description><![CDATA[
<p>> Huh? It queries whenever you stop typing.<p>That's relatively infrequently - TabNine offered me accurate completion while still writing my code, whereas with Copilot I not only have to wait for it to return the answer, I also have to <i>hope</i> it knows an answer. If it doesn't, too bad, lost time for nothing.</p>
]]></description><pubDate>Wed, 22 Jun 2022 10:12:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=31833981</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=31833981</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31833981</guid></item><item><title><![CDATA[New comment by arcatek in "Monorepos in JavaScript and TypeScript"]]></title><description><![CDATA[
<p>The article doesn't go into how to integrate TypeScript in the monorepo for development - what we do on the Yarn repository is that we point all the package.json `main` fields to the TypeScript sources, then use `publishConfig.main` to update it to the JS artifacts right before being published.<p>This way, we can use babel-node or ts-node to transparently run our TS files, no transpilation needed.</p>
]]></description><pubDate>Thu, 02 Jun 2022 17:00:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=31597491</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=31597491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31597491</guid></item><item><title><![CDATA[New comment by arcatek in "pnpm: Fast, disk space efficient package manager for JavaScript"]]></title><description><![CDATA[
<p>> If there are clearly better algorithms, why not refactor npm and add them in experimental flags to npm<p>While node_modules has many flaws, in the current ecosystem all modes have their own pros and cons, and there isn't a "clearly better" algorithm: node_modules has less friction, PnP is sounder, and pnpm's symlinks attempt to be kind of an in-between, offering half the benefits at half the "cost".<p>Like in many computer science things, it's tradeoffs all the way. Part of why Yarn implements all three.</p>
]]></description><pubDate>Tue, 05 Apr 2022 19:12:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=30923536</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=30923536</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30923536</guid></item><item><title><![CDATA[New comment by arcatek in "Fetch API has landed into Node.js"]]></title><description><![CDATA[
<p>Usually you setup a transpiler to target both. For example, my packages are bundled with rollup towards both cjs & esm:<p><a href="https://github.com/arcanis/clipanion/blob/master/rollup.config.js#L6-L17" rel="nofollow">https://github.com/arcanis/clipanion/blob/master/rollup.conf...</a></p>
]]></description><pubDate>Tue, 01 Feb 2022 15:47:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=30164059</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=30164059</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30164059</guid></item><item><title><![CDATA[New comment by arcatek in "Fetch API has landed into Node.js"]]></title><description><![CDATA[
<p>However note that ESM in Node comes with drawbacks that prevent end-users from relying them in various situations. Those will be mostly solved once loaders become stable, but until then it's still advised to ship packages as both CJS and ESM.</p>
]]></description><pubDate>Tue, 01 Feb 2022 13:37:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=30162166</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=30162166</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30162166</guid></item><item><title><![CDATA[New comment by arcatek in "Gitlab Epic Issue Relationships Deleted"]]></title><description><![CDATA[
<p>Out of curiosity, how do transaction logs handle things like created_at fields, or randomly generated UUID, which rely on contextual data? Is the server time/rng seed faked for each replayed transaction?</p>
]]></description><pubDate>Wed, 15 Dec 2021 13:22:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=29565531</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=29565531</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29565531</guid></item><item><title><![CDATA[New comment by arcatek in "Security issue related to the NPM registry"]]></title><description><![CDATA[
<p>To reiterate on what sibling comments said, I'm the one who spawned the discussion and implementation of Corepack, and npm remained largely out of it; the push mostly came from pnpm and Yarn.<p>Additionally, unlike other approaches, Corepack ensures that package manager versions are pinned per project and you don't need to blindly install newest ones via `npm i -g npm` (which could potentially be hijacked via the type of vulnerability discussed here). It intends to make your projects more secure, not less.</p>
]]></description><pubDate>Wed, 17 Nov 2021 08:44:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=29250472</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=29250472</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29250472</guid></item><item><title><![CDATA[New comment by arcatek in "Bitcoin is largely controlled by a small group of investors and miners"]]></title><description><![CDATA[
<p>If they start to play with different rules, one of the hard fork remaining branches (or both) will be refused by everyone on the network and be worthless.<p>There's no telling whether it'd be the "hijacked" branch or the original one - assuming they control 50%+ of the mining power, there's a decent argument that the remaining miners would follow their lead if only to stay on the largest branch.</p>
]]></description><pubDate>Wed, 27 Oct 2021 10:12:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=29011303</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=29011303</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29011303</guid></item><item><title><![CDATA[New comment by arcatek in "GitHub Actions checkspelling community workflow GitHub_TOKEN leakage via symlink"]]></title><description><![CDATA[
<p>I was under the impression that the default temporary GITHUB_TOKEN for forked repos (which is what happens with PRs) were read-only. Isn't that the case?<p><a href="https://docs.github.com/en/actions/reference/authentication-in-a-workflow#permissions-for-the-github_token" rel="nofollow">https://docs.github.com/en/actions/reference/authentication-...</a></p>
]]></description><pubDate>Thu, 09 Sep 2021 08:32:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=28467547</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=28467547</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28467547</guid></item><item><title><![CDATA[New comment by arcatek in "C++ Exceptions: Under the Hood (2013)"]]></title><description><![CDATA[
<p>It's public, but I doubt it still compiles against recent LLVM versions! I started it 8 years ago to get a better understanding how features like classes & operator overload would work in a JS-like language. It was really fun!<p><a href="https://github.com/castel/libcastel/blob/master/runtime/sources/runtime/interfaces/exceptions.cc#L36" rel="nofollow">https://github.com/castel/libcastel/blob/master/runtime/sour...</a><p><a href="https://github.com/castel/libcastel/blob/master/runtime/sources/runtime/helper/LSDA.cc" rel="nofollow">https://github.com/castel/libcastel/blob/master/runtime/sour...</a><p>I remember that at the time there were very few resources on personality functions, even in the LLVM doc - I had to make a lot of research before finding your articles, which were extremely helpful!<p>I got reminded of them yesterday after someone pinged me on a Stack Overflow answer I made at the time, asking for an updated link; after I found your long-form article I figured it would be a good topic for HN as well :)<p><a href="https://stackoverflow.com/questions/16597350/what-is-an-exception-handling-personality-function" rel="nofollow">https://stackoverflow.com/questions/16597350/what-is-an-exce...</a></p>
]]></description><pubDate>Fri, 13 Aug 2021 11:22:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=28167644</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=28167644</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28167644</guid></item><item><title><![CDATA[New comment by arcatek in "C++ Exceptions: Under the Hood (2013)"]]></title><description><![CDATA[
<p>That's the article I used when I implemented exceptions in an LLVM-based compiler, so it's applicable to more than just GCC.</p>
]]></description><pubDate>Thu, 12 Aug 2021 22:45:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=28162574</link><dc:creator>arcatek</dc:creator><comments>https://news.ycombinator.com/item?id=28162574</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28162574</guid></item></channel></rss>